related-party-identification

Warn

Audited by Snyk on Aug 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 本 skill 在运行时会读取用户触发的 cicpa-company-query 批量下载并解压得到的 _files/ 里多家公司 Excel 文本字段(如电话、邮箱、地址、姓名、关联方标注等),因此若这些数据源包含外部用户/第三方提交的自由文本则会被 LLM/脚本实际消费并参与关联规则比对。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 01:29 AM
Issues
1
Security Audit — snyk — related-party-identification