wjs-mining-voicedrop
Warn
Audited by Snyk on Jun 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). 该 skill 在运行时会从外部来源(Cloudflare R2 的
jianshuo.dev/files)下载VoiceDrop-*.m4a,随后把音频交给wjs-transcribing-audio进行转写;转写结果(SRT/文本)会进入后续 LLM 上下文用于挖文章,因此存在“外部录音内容→LLM上下文”的间接提示注入风险。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata