lit-search

Fail

Audited by Snyk on Aug 3, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). Several URLs point to direct downloads of executable packages/archives (Windows .exe, Debian .deb, .7z/.zip) hosted on a general-purpose repository (Zenodo); direct executables from such third‑party hosting are a common vector for malware and should be treated as high risk unless you explicitly trust and verify the publisher and checksums.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 运行时从用户自提供的 topics/<id>.yaml 生成检索式后,lit harvest/lit proceedings 会通过外部来源(如 OpenReview/CVF/Zenodo/PubMed/OpenAlex/Crossref 等)读取其返回的文本/元数据并在后续 LLM lit screen 中摄入用于筛选判定,因此存在“外部作者文本→LLM读取”的间接提示注入面。

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 3, 2026, 12:04 AM
Issues
2
Security Audit — snyk — lit-search