zettaranc-perspective
Warn
Audited by Snyk on Apr 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's required workflow (SKILL.md Step 2: "必须使用工具(WebSearch等)获取真实信息") explicitly instructs the agent to fetch and research public/web sources (e.g., B站直播 recordings, fan transcripts, comments and other public articles listed in the references), so it ingests untrusted user-generated third‑party content that will directly influence analysis and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata