tw-research-proposal-diamond
Warn
Audited by Snyk on May 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's workflow (SKILL.md phases 1–4, e.g., "立刻使用
web_search搜尋" in Phase 1 and "使用web_search補充具體引用文獻(至少 5 筆)" in Phase 4) explicitly instructs the agent to fetch and ingest open/public web content and use those results to shape research directions and outputs, so untrusted third‑party content can materially influence its actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata