copy-title-generator
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md "流程1:生成标题(增强版)" explicitly instructs calling the search tool aisearch-mcp-server__chatCompletions to fetch topical/hot events and cases from the web and then "提取关键信息" and "融入热点元素" into generated titles, which means untrusted third‑party content is fetched and directly drives generation decisions.
Audit Metadata