enterprise-info
Warn
Audited by Snyk on Aug 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md/scripts/query.py at runtime ingests outsider-provided free text via the user argument
words(company name/credit code), sends it tohttps://cn.apihz.cn/api/shiming/qyinfo.php, and then reads and formats the API’s returned JSON fields into the agent output.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata