baoyu-post-to-wechat

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill downloads and renders arbitrary remote content from markdown and extensions—e.g., scripts/md-to-wechat.ts resolves and downloads HTTP(S) image URLs via downloadFile, and scripts/md/extensions/plantuml.ts (fetchSvgContent) fetches SVGs from public PlantUML (default https://www.plantuml.com/plantuml)—which are untrusted third-party sources that the agent ingests and incorporates into the posting workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 10:58 AM