wechat-article-to-markdown

Warn

Audited by Snyk on Aug 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该 Skill 的运行时会对用户提供的 mp.weixin.qq.com 链接同时执行 stealthy_fetch 并摄取返回的 HTML/Markdown 正文内容(用于提取图片与文本),因此外部作者可通过发布文章内容对工作流输入进行间接提示注入。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:34 PM
Issues
1
Security Audit — snyk — wechat-article-to-markdown