bilibili-comments
Warn
Audited by Snyk on Jun 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The script fetches Bilibili comment text (including
content.message) from Bilibili’s API responses inside the logged-in Chrome page context viabrowserFetchJson(...)→evalInPage(...)→fetch(...), so the LLM context can receive outsider-authored free text from third-party users’ comments.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata