rdq-opencode
Warn
Audited by Snyk on Jul 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Runtime LLM context can include outsider-authored free text from the operating user’s conversation (user messages themselves are treated as outsider content relative to the skill), which this skill directly ingests and echoes in Phase 1 “回顯使用者說的話”.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata