competition-bundle-sourcemap-recovery
Fail
Audited by Snyk on Jun 20, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). 该技能明确要求记录并保留“endpoint strings”和“config keys”及确切执行的 bundle/module 内容,要求模型处理并输出这些值(可能包含 API 密钥或密码),存在将敏感凭据逐字复述并外泄的高风险。
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). At runtime the skill instructs the agent to “Start from the served artifact set” (entry HTML, build manifest, bootstrap bundle, chunk map, and source maps) and to load those served assets/URLs for analysis, which commonly includes outsider-authored web content or downloaded artifacts not authored by the operating user.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata