competitive-teardown

Warn

Audited by Snyk on Jun 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.72). Outsider free text can be ingested because the skill explicitly accepts “竞品官网 / 定价页 / changelog / 用户评论 / 销售反馈 / 内部调研笔记” and “链接摘录” as inputs, which at runtime may include scraped/forwarded third-party user comments or other non-user-authored competitor materials that the agent then summarizes into the LLM context.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 20, 2026, 02:05 PM
Issues
1
Security Audit — snyk — competitive-teardown