hankookilbo-news
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). instruction.md의 Workflow/endpoint contract에 따라 에이전트가 mcp.hankookilbo.com의 tools/call 결과인 기사 메타데이터(items.title/items.excerpt 등)와 서버가 내려주는 “instructions”을 그대로 처리/전달하며, 이 텍스트는 한국일보(제3자)가 작성한 콘텐츠(기사 제목/발췌)로서 사용자 발화에 의해 간접적으로 선택·수집됩니다.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's required first step runs "npx -y @nomadamas/k-skill@0 instruct hankookilbo-news", which fetches and executes remote package code that provides the primary runtime instructions (see https://github.com/NomaDamas/k-skill/blob/main/hankookilbo-news/instruction.md), so external content controls agent behavior at runtime.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata