hankookilbo-news

Warn

Audited by Snyk on Aug 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). instruction.md의 Workflow/endpoint contract에 따라 에이전트가 mcp.hankookilbo.com의 tools/call 결과인 기사 메타데이터(items.title/items.excerpt 등)와 서버가 내려주는 “instructions”을 그대로 처리/전달하며, 이 텍스트는 한국일보(제3자)가 작성한 콘텐츠(기사 제목/발췌)로서 사용자 발화에 의해 간접적으로 선택·수집됩니다.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill's required first step runs "npx -y @nomadamas/k-skill@0 instruct hankookilbo-news", which fetches and executes remote package code that provides the primary runtime instructions (see https://github.com/NomaDamas/k-skill/blob/main/hankookilbo-news/instruction.md), so external content controls agent behavior at runtime.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 1, 2026, 03:02 AM
Issues
2
Security Audit — snyk — hankookilbo-news