folio
Warn
Audited by Snyk on Aug 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Folio 的必需运行时“Step 1:消化来源”会读取用户提供的 URL/文件/粘贴文本(不受信任数据),并将其中可读自由文本进入后续“建立内容核心→派生 publish-info / figure-spec / article-draft”的处理链。
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly accepts and processes external source URLs at runtime (e.g., it runs "$folio https://github.com/geeklee/srt-whiteboard-animation" and treats fetched page/repo contents as source material that get serialized into prompts), so remote content from URLs such as https://github.com/geeklee/srt-whiteboard-animation and example signature URLs like https://example.test/export?signature=secret can directly influence the generated prompts and thus pose a runtime injection/exfiltration risk.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata