goofish-overview

Warn

Audited by Snyk on Aug 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该 skill 通过 MCP 工具在运行时会读取来自外部消息系统的文本:goofish-reply-buyer 的工作流通常会先调用 mcp__goofish__message_list_chats / mcp__goofish__message_history 把买家消息内容喂给 LLM 再起草回复,从而存在被任意买家“投喂”提示注入的间接风险。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 14, 2026, 05:37 AM
Issues
1
Security Audit — snyk — goofish-overview