jcm-article-writing

Warn

Audited by Snyk on Jul 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). 该 skill 的运行流程包含“联网检索并整理资料/读取网页正文”(SKILL.md:159-165、169-173),这会把运行时抓取的公开网页自由文本(xcrawl/Web Search 结果)注入到后续 LLM 上下文中,属于外部来源的间接提示注入风险。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 13, 2026, 01:07 PM
Issues
1
Security Audit — snyk — jcm-article-writing