wenqu-library
Warn
Audited by Snyk on Aug 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 文库Skill的运行时会把用户/上游给定的“收集清单”里的关键词交给“agent 自带的联网搜索工具”和可选的open-websearch搜索,从而在检索结果(标题/描述/链接摘要)中摄入外部可由他人撰写的自由文本,再参与候选合并与后续下载。
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill explicitly instructs the agent to perform "global installation" and "browser setup" itself after user authorization (not asking the user to run commands), which directs the agent to modify the host system state and could require elevated privileges.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata