deep-research-report

Fail

Audited by Snyk on Aug 9, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The URL points to a GitHub repository from an individual account that the skill instructs you to install/run (including an npx install), which can execute unreviewed code—so while hosted on GitHub (a common source), it is untrusted and potentially risky to install directly without code review.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Mode Aの必須実行フローで、利用者が貼り付けた調査結果(MD/テキスト/チャット出力/ファイル内容/ファイルパスの中身)を原文としてLLMが通読・編集してHTMLレポート化するため、第三者が投稿した自由記述がそのまま入力として読まれ得ます(さらに数値照合等も行う前提)。

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 9, 2026, 02:13 PM
Issues
2
Security Audit — snyk — deep-research-report