light-idea-critique
Warn
Audited by Snyk on Jul 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Step 2 “检索取证”会在运行时调用外部检索(OpenAlex/Semantic Scholar/OpenReview)并把返回的 abstract/文本作为 data 读入 LLM 上下文;该外部来源属于“公共 web 内容/外部 API 返回的文本”。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata