lexiang-knowledge-base

Fail

Audited by Snyk on Aug 19, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly asks the user to provide their access_token and instructs replacing placeholders in mcp.json / exporting LEXIANG_TOKEN, which requires the agent to receive and potentially emit the secret value verbatim.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该 Skill 的运行路径在执行“读取条目正文内容”时会调用 entry_describe_ai_parse_content 来摄取乐享知识条目正文(用户可通过其提供的 space_id/entry_id//spaces///pages/ 指向任意条目),因此越权/投毒条目中的自由文本会在运行时被 LLM 读取;这是外部作者通过向乐享提交内容实现的间接提示注入风险。

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 19, 2026, 07:46 PM
Issues
2
Security Audit — snyk — lexiang-knowledge-base