create-mao
Warn
Audited by Snyk on Apr 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly instructs ingesting public, user-accessible works into its knowledge/ directory and cites open/public sources (e.g., CONTRIBUTING.md "获取著作的渠道" and knowledge/README.md listing marxists.org, 学习强国, university digital resources) and the repo's MEMORY.md even lists an installed opencli-operate tool for browsing arbitrary URLs, so the agent is expected to fetch and parse untrusted third‑party web content which can materially affect its outputs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata