moshu-research

Warn

Audited by Snyk on Aug 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). runtime 内部会 spawn moshu-researcher agent 并在其 query/context 中携带用户触发的采风需求,且该 agent 的“检索与蒸馏”明确会抓取公开来源文本以生成 设定/采风-CF*.md,因此外部作者可通过其发布内容影响被 LLM 读取的免费文本(典型为 web/平台页面简介/目录标题等摘要文本)。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 07:58 AM
Issues
1
Security Audit — snyk — moshu-research