lov-personal-vocabulary
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md 的 Step 2 在 app-adapters 中直接读取用户指定的本地 OpenLess dictionary.json 或通过 Typeless API 拉取其词条(用户凭据下只读探测),这些词条内容会进入运行时进行映射/合并/差异计算。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata