cheat-trends

Warn

Audited by Snyk on Jul 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). SKILL.md: Phase 1-2 的各 adapter 的 fetch 会进行 WebFetch/抓取(如 manual-paste 会对用户提供的 URL 做 WebFetch 拓展 snippet;aihot/weibo-hot/zhihu-hot/trendradar-mcp 会拉取外部热门内容),从而把“非用户原创的网页/帖子正文”作为可读 snapshot_text/rationale 等进入 Phase 4 的 LLM打分上下文,存在间接提示注入风险。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 23, 2026, 04:05 AM
Issues
1
Security Audit — snyk — cheat-trends