tianxiabachang-perspective
Warn
Audited by Snyk on May 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The liucixin-skill SKILL.md explicitly requires using external tools to verify scientific facts ("⚠️ 涉及科学概念时必须使用工具核实,不可凭训练语料编造") and its Step 3 says answers must be based on the facts gathered, while the skill's "调研来源" lists public media/interview/web sources (e.g., 科幻世界、新华社、媒体专访), which together show the agent is expected to fetch and interpret untrusted third‑party content that can materially influence its outputs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata