bear-propose
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.72). 该 skill 在 Step 1/3/4 通过
sci search进行运行时学术检索,随后把检索返回的论文title/authors/year/abstract等可读文本(来自外部出版物/数据库的内容,非用户自写)注入到 LLM 生成的report.md/report.html与摘要折叠中,属于“公共/外部检索内容(论文元数据与摘要)→ LLM 上下文”的间接提示注入风险路径。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata