当需要其他 agent 的专长、上下文或协作支持,或用户明确要求调用其他 agent 时,使用本 skill。先查询可用 agents,再用 qwenpaw agents chat 进行双向沟通。
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
SKILL.md 规定会通过 `qwenpaw agents chat` 把对“其他 agent”的 `--text`(以及后续由其他 agent 产出的消息内容)进入对话上下文;由于目标 agent 的回复属于非操作用户/非你编写的内容,属于“其他 agent 产出的免费文本”这一类间接提示注入风险。
1a4f4d8
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.