bmz-preflight
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在
/bmz-preflight的运行流程中会直接读取并处理用户在“输入素材/作品信息”里提供的自由文本(如歌词、prompt、标题、标签、作品说明),这些文本属于外部用户可控内容,可能包含间接提示注入但需先完成体检而非先验选择特定条目;因此存在中等间接注入风险。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata