skill-publish-verify
Warn
Audited by Snyk on Aug 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在
scripts/nodes/agent_run.py的agent_runTO_AGENT 节点中,agent 会从隔离环境读取skill_dir/SKILL.md并“自行决定怎么跑”且把过程产物写入run_record.json,因此其运行工作流直接摄入了由 skill 作者提供的自由文本(SKILL.md 内容)。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata