board-minutes

Warn

Audited by Snyk on May 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflow explicitly asks the agent to ingest external meeting materials/presentations ("第3步:材料 — 你能分享本次会议的议程和预读材料吗...上传这些——我将用它们填充议程项目摘要") and to "检索适用的公司法" when the charter lacks quorum rules (in "法定人数"), meaning it will fetch and interpret public/third‑party legal sources and user-provided documents that can materially change drafting and next actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 15, 2026, 07:07 AM
Issues
1
Security Audit — snyk — board-minutes