soia-pkm-clip-github-repo
Warn
Audited by Snyk on Jul 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). 在运行时该工作流会从“outsider”的 GitHub 上游仓库克隆目录读取 README 文本并抽取简介(scripts/gen_repo_catalog.py:296-349, 219-232, 238-245)作为卡片正文写入/再进入上下文;同时还会遍历 notes_dir 下现有调研笔记并读取其 frontmatter
关联仓库(scripts/gen_repo_catalog.py:407-428, 460-472, 355-375),这些笔记内容可能由非操作用户/外部来源撰写。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata