content-digest

Warn

Audited by Snyk on Aug 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md 的流程在第1步“Obtain the Content”中会对用户提供的 URL 使用 WebFetch(YouTube/文章/播客转录)或直接读取用户提供的文本全文,并在后续“Deep Analysis”中要求模型通读这些内容后提取观点,因此会把外部/用户提交的自由文本(从可被污染的网页/转录/文章/文本中)直接喂给LLM。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 02:09 AM
Issues
1