social-content-kit

Fail

Audited by Snyk on Aug 19, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). One input URL contains a signed query parameter exposing a secret (possible private download or tokenized link) and another is an unreachable/placeholder domain used to reference a missing project — these two entries are suspicious while the remaining GitHub and example.com links are standard documentation or repo references and are lower risk.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md 的 Step 1 明确把用户提供的 URL、文件或粘贴文本作为不受信任数据“待分析”,并在后续建立内容核心与派生 publish-info/figure-spec 时读取这些文本,从而使外部作者可通过提交输入进入运行时上下文。

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 19, 2026, 03:25 AM
Issues
2
Security Audit — snyk — social-content-kit