douyin-daily-hot
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In scripts/douyin_daily_hot.py the workflow only ingests outsider-authored free text from user-controlled CLI arguments (e.g., --type/--start/--end/--full) and uses them as query parameters to a first-party API, while the actual LLM output text is composed from trusted API response fields (title/workUrl) rather than directly from arbitrary outsider free-text submissions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata