lit-search
Fail
Audited by Snyk on Aug 3, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). Several URLs point to direct downloads of executable packages/archives (Windows .exe, Debian .deb, .7z/.zip) hosted on a general-purpose repository (Zenodo); direct executables from such third‑party hosting are a common vector for malware and should be treated as high risk unless you explicitly trust and verify the publisher and checksums.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 运行时从用户自提供的
topics/<id>.yaml生成检索式后,lit harvest/lit proceedings会通过外部来源(如 OpenReview/CVF/Zenodo/PubMed/OpenAlex/Crossref 等)读取其返回的文本/元数据并在后续 LLMlit screen中摄入用于筛选判定,因此存在“外部作者文本→LLM读取”的间接提示注入面。
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata