eudic-to-anki

Warn

Audited by Snyk on May 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly exports data from the third‑party Eudic service (see SKILL.md step 3 and modules/export/README.md using python3 scripts/eudic_export.py and references/openapi.md), preserves Eudic's context_line as source_context, and requires the agent to use that source_context when authoring coach JSON and examples (modules/coach/README.md and references/word-coach-json-prompt.md), so arbitrary user/web-origin content from an external service is ingested and can materially influence the agent's decisions and actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 11, 2026, 03:30 AM
Issues
1