insane-research-main

Warn

Audited by Snyk on Aug 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md의 Phase 3 “Iterative Querying” 및 Phase 4 “Source Triangulation”는 사용자 주제로부터 WebSearch/WebFetch/Bash로 외부 웹페이지·피드·문서(예: Reddit JSON API 등)를 검색/가져와 추출 내용을 sources/sources.jsonl로 LLM에 주입하므로, outsider가 작성한 텍스트를 통해 간접 프롬프트 인젝션이 가능해집니다.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 1, 2026, 04:01 PM
Issues
1
Security Audit — snyk — insane-research-main