kindle-weread-setup
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). 在 SKILL.md 的运行流程中,模型在“当日来源与路由门禁/KOReader 与 WeRead 阶段”会联网读取第一方在 README/skill 中列出的固定 URL(如 kindlemodding.org、github.com wiki/release),而不是从外部用户可投递的任意文本源先行摄入;同时问诊与平台信息主要来自用户提供的设备信息而非“外部可发布文本队列/流”。
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly requires live checks and downloads from external release/docs pages (e.g., https://kindlemodding.org/jailbreaking/ and https://github.com/koreader/koreader/wiki/Installation-on-Kindle-devices) which the agent must fetch at runtime to determine and follow jailbreak/install commands, so external content directly controls agent instructions.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata