cheat-seed

Fail

Audited by Snyk on Jul 23, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). This is a third‑party GitHub repository (a personal account) that the skill instructs users to clone and run; personal GitHub repos can distribute unvetted code and thus pose a potential malware risk unless the author and project are verified.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.72). 在 Mode C(以及时事灰色场景用户选择“看”)路径里,运行时会调用外部热点数据源(如 trendradar-mcp / aihot 或 manual-paste 的 URL/标题),把其检索到的可读正文/条目与标题 inline 到 LLM 上下文用于后续“聊经历兜底”和生成 draft,因此存在“公网页/外部素材—自由文本—进入 LLM 上下文”的间接提示注入风险。

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 23, 2026, 04:05 AM
Issues
2
Security Audit — snyk — cheat-seed