news-to-note

Warn

Audited by Snyk on Jun 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). 工作流 B 在运行时会对用户提供的 URL/话题执行 WebFetch/WebSearch 抓取网页正文,并将其作为“正文”分段写入笔记后再用于 LLM 产出 insight,因此会把外部网页(OUTSIDER)自由文本喂入上下文。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 24, 2026, 06:44 AM
Issues
1
Security Audit — snyk — news-to-note