yzr-llm-workspace-management
Warn
Audited by Snyk on Aug 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 该 skill 在运行时会读取并在跨 wiki 工作前展开
<workspace>/AGENTS.md以及其中通过@MEMORY/MEMORY.md引用的<workspace>/MEMORY/MEMORY.md(由@机制加载),而这些文件的内容来自用户/本地 workspace,属于外部可被“作者者”控制的自由文本输入面。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata