douyin-comment

Warn

Audited by Snyk on Jun 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.95). 运行时通过 douyin_comment_search.py 调用 Redfox API 获取抖音评论文本(data.commentList[].text),这些为第三方/外部用户(非操作用户)撰写的自由文本,并在 Step 3 的 A2/A3 中被直接拼入对话与用于 AI 总结分析。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 26, 2026, 10:59 PM
Issues
1
Security Audit — snyk — douyin-comment