job-article

Warn

Audited by Snyk on May 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). Yes — the workflow's Step 2 "搜集资料" explicitly requires using联网搜索 (e.g., "web_search") to fetch current open-web sources (companies, salary data,面经), and those third‑party results are required inputs that the agent must read and use to shape article content and decisions (e.g., labeling sources as "网传" vs "已确认").

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 06:20 AM
Issues
1
Security Audit — snyk — job-article