ai-intelligence-investigator
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在
references/core_workflow.md的“广域扫描/深度挖掘/交叉验证”中,技能会基于用户调查需求用 Baidu/东方财富/同花顺/雪球/巨潮资讯/微博/WeChat/Reddit 等引擎进行关键词搜索并读取结果文本(包含外部用户撰写内容),从而形成旁路提示注入风险。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata