cheat-seed
Fail
Audited by Snyk on Jul 23, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). This is a third‑party GitHub repository (a personal account) that the skill instructs users to clone and run; personal GitHub repos can distribute unvetted code and thus pose a potential malware risk unless the author and project are verified.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.72). 在 Mode C(以及时事灰色场景用户选择“看”)路径里,运行时会调用外部热点数据源(如 trendradar-mcp / aihot 或 manual-paste 的 URL/标题),把其检索到的可读正文/条目与标题 inline 到 LLM 上下文用于后续“聊经历兜底”和生成 draft,因此存在“公网页/外部素材—自由文本—进入 LLM 上下文”的间接提示注入风险。
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata