requirements-doc-gen
Warn
Audited by Snyk on Mar 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's workflow explicitly instructs the agent to "使用
web_search搜索相关规范和最佳实践" and "将搜索结果整合到文档中" (SKILL.md, 场景一 步骤 6), which requires fetching and interpreting open web content that can be untrusted and can materially change generated documents.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata