llm-wiki-setup
Warn
Audited by Snyk on Jul 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Required workflow includes Phase 4 “首次 ingest 演示” where the operating user provides a “真实的源(研报 / 电话会 / 纪要)” and the system ingests it into the vault; this is outsider-authored free text (the source documents are not authored by the operating user) that can become LLM-readable prose during ingest.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata