ai-intelligence-investigator

Warn

Audited by Snyk on Aug 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 在 references/core_workflow.md 的“广域扫描/深度挖掘/交叉验证”中,技能会基于用户调查需求用 Baidu/东方财富/同花顺/雪球/巨潮资讯/微博/WeChat/Reddit 等引擎进行关键词搜索并读取结果文本(包含外部用户撰写内容),从而形成旁路提示注入风险。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 09:46 AM
Issues
1
Security Audit — snyk — ai-intelligence-investigator