binlee-articles
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly sources and refreshes article content from the public site https://drli.beaucare.org (see SKILL.md "来源" and source_url) and the fetch_drli.mjs script, stores those articles in ~/drli_articles/, and the provided search/query scripts/readers directly load and interpret those JSON article contents as part of normal workflow—meaning untrusted third-party text can influence agent behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata