seedream-image

Warn

Audited by Snyk on Feb 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly states the skill performs "Real-time Web Search" and "联网触发" (auto-fetches trending/external info when prompts contain time-sensitive or hot-topic keywords), and reference.md lists external URLs, so the agent will fetch and interpret open/public third-party web content that can influence prompt-generation and subsequent actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 20, 2026, 09:57 AM