bettafish-opinion-analysis

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's SKILL.md and references/data_sources.md explicitly require QueryAgent/MediaAgent/InsightAgent to perform WebSearch/WebFetch/Browser/Curl on public websites and social media (e.g., site:weibo.com, xiaohongshu, 抖音, B站) and feed those findings into the ForumEngine for multi-round analysis and report generation, so untrusted third‑party content is fetched and directly influences agent decisions and tool use.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 10:03 AM