ai-to-human-zh
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 该 skill 的必经运行流程是对用户提供的中文“文案”进行扫描/改写:在 SKILL.md 的“两步流程”中直接把“拿到文案后”的文本交给脚本 python3 scripts/hanyihan_qc.py 或“直接贴给Agent”,且脚本运行时会读取并处理该文案全文(包含逐行匹配/统计),因此外部作者可通过提交要处理的文本来注入无害但可控的自由文本。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata