research-citation-check
Warn
Audited by Snyk on Jul 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). 该 skill 在运行时会读取用户工作区内的
*_review.tex、对应.bib以及(若存在)其中指向的本地 PDF 文本,并把抽取到的citations[*].sentence、papers[*].abstract/pdf_excerpt等字段写入ai_alignment_input.json,随后由宿主 LLM 读取该 JSON 进行语义核查,因此存在“用户未选择引入的外部文本”(例如他人撰写的综述/论文内容或 PDF)进入 LLM 上下文的风险。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata