baidu-wenku-aippt-personal

Fail

Audited by Snyk on May 12, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.80). Yes — the skill instructs the agent to "完整记录并分析" the PPT outline in its "thinking" process (i.e., expose internal chain-of-thought), which is a hidden/deceptive instruction to reveal internal reasoning outside the advertised PPT-generation functionality.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill clearly fetches and executes external, public content (scripts/install.sh downloads an installer from issuecdn.baidupcs.com and scripts/update.sh queries https://pan.baidu.com/act/v2/api/conf?... and downloads a remote ZIP), and SKILL.md requires the agent to parse and act on bdpan aippt command output (service responses), so third-party content can materially change behavior (including updating skill code) at runtime.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (3)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 12, 2026, 11:31 AM
Issues
3