binlee-articles

Warn

Audited by Snyk on May 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly sources and refreshes article content from the public site https://drli.beaucare.org (see SKILL.md "来源" and source_url) and the fetch_drli.mjs script, stores those articles in ~/drli_articles/, and the provided search/query scripts/readers directly load and interpret those JSON article contents as part of normal workflow—meaning untrusted third-party text can influence agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 13, 2026, 06:47 AM
Issues
1
Security Audit — snyk — binlee-articles