douyin-keyword-collector
Warn
Audited by Snyk on Aug 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In “Douyin Keyword Collector,” the required runtime workflow uses a browser to navigate to https://www.douyin.com, types a user-supplied keyword, and then snapshots/reads the free-text search suggestion prompt box from the site for output, which is outsider-authored UI content that could include injected text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata