integration-management

Warn

Audited by Snyk on May 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly ingests and parses external transaction documents (e.g., "上传或已连接的文件路径" in 模式1, "你的合同存储库是否已连接?…我将拉取…并逐份读取" in 模式2, and "上传来自[外部律师/…]的状态更新。我将解析并更新追踪器" in 模式4), meaning it consumes untrusted/third‑party user-generated content and uses that content to drive decisions and workflow actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 15, 2026, 07:07 AM
Issues
1
Security Audit — snyk — integration-management