aminer-pdf-citation-verifier

Warn

Audited by Snyk on Jul 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). This skill polls AMiner’s GET /api/v3/paper/citation/result and (when is_finish: true) additionally GETs urls.result, then inlines the returned resp.json() as payload["details"] that is finally echoed to stdout—i.e., outsider-authored response text (from a third-party service’s per-reference JSON) is ingested into the agent context.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 22, 2026, 03:07 AM
Issues
1
Security Audit — snyk — aminer-pdf-citation-verifier