1-web-pack
Warn
Audited by Snyk on Jul 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). 该技能会在运行时通过 HTTP 抓取入口网页/相关链接的正文文本(
scripts/collect_web_pack.py里session.get(...).text并在base._extract_article_soup/_blocks_to_markdown中转成 Markdown),这些内容属于外部网页作者的自由文本,且还可能在 direct 抓取失败/弱时经r.jina.ai兜底进一步读取为纯文本(同样属于外部文本)。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata