hmos-apifault-analysis
Warn
Audited by Snyk on Jun 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). 在阶段1“日志采集与解析”中,若用户未提供日志则会通过
references/scripts/hilog_collector.py在运行时从设备拉取并解析 hilog 文本(parsed_files逐个builtin_read_file读入),这些 hilog 内容属于非操作用户/非本地项目作者的外部来源,可能包含自由文本从而进入 LLM 上下文。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata