soia-pkm-clip-github-repo

Warn

Audited by Snyk on Jul 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). 在运行时该工作流会从“outsider”的 GitHub 上游仓库克隆目录读取 README 文本并抽取简介(scripts/gen_repo_catalog.py:296-349, 219-232, 238-245)作为卡片正文写入/再进入上下文;同时还会遍历 notes_dir 下现有调研笔记并读取其 frontmatter 关联仓库(scripts/gen_repo_catalog.py:407-428, 460-472, 355-375),这些笔记内容可能由非操作用户/外部来源撰写。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 22, 2026, 01:49 PM
Issues
1
Security Audit — snyk — soia-pkm-clip-github-repo