sentiment-monitor
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's workflow (SKILL.md and references/platform-guide.md) explicitly instructs using opencli to fetch comments and posts from public, user-generated sources (微博/知乎/B站/小红书/抖音) and references/analysis-guide.md shows an LLM prompt that ingests those comments for labeling and report construction, meaning untrusted third‑party content is read and can materially influence subsequent analysis and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata