apple-smart-schedule
Warn
Audited by Snyk on Aug 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 解析的“用户消息文字/截图内容”会在运行时被 LLM 用于抽取事件字段并据此调用创建脚本(SKILL.md 第1-4步),因此外部作者只需向该 skill 的输入渠道提交文本/截图即可影响 LLM 读取。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata