hotdaily

Warn

Audited by Snyk on Jul 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.78). 该 skill 在运行时通过 HotDaily API(如 /v1/digests/*/v1/trends/*/v1/items/{id})把聚合后的文章标题/摘要/正文等“可读文本”喂给 LLM;这些内容来源于 Hacker News、Lobsters 等第三方社区的用户帖子/文章(外部作者),属于公共/第三方内容经 API 返回后的自由文本间接注入风险。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 3, 2026, 01:21 AM
Issues
1
Security Audit — snyk — hotdaily