axhub-commentary

Warn

Audited by Snyk on Jul 31, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 所需工作流在“低频页面/环境读取”之外,会在运行时直接读取并处理本地项目内的 comments.json(并按 assets/ 里的相对路径读取图片资源),而这些文本可由同一租户的使用者/协作者在项目中任意提交,因此存在被外部作者注入的间接风险。

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill spawns npx to fetch and run the remote package "@axhub/acp@latest" at runtime (e.g., the command "npx -y @axhub/acp@latest"), which executes remote code as part of normal operation.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 31, 2026, 09:28 AM
Issues
2
Security Audit — snyk — axhub-commentary