story-long-analyze

Fail

Audited by Snyk on Aug 24, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). This is a GitHub repository referenced as the skill's source but hosted under an unfamiliar account (zenstory-ai); third‑party GitHub repos from unknown/low‑profile users can contain malicious code or installers, so treat downloads from it as potentially suspicious until verified.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该技能在 Stage 1/2 会读取“用户提供的源路径/对话中贴出的小说文本”,并将原文分片后直接喂给子代理(chapter-extractor)进行情节点与摘要提取;因此外部用户可通过提交小说文本本身向运行时注入任意自由文本。

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 24, 2026, 03:17 PM
Issues
2
Security Audit — snyk — story-long-analyze