douyin-works-crawler
Warn
Audited by Snyk on Jun 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). 运行时通过
POST https://redfox.hk/story/api/dyData/queryUserWithWorks获取的data.workList[*].title/nickname/url等字段会被直接拼接进format_markdown()的 Markdown 输出,从而把“抖音账号/作品的外部文本内容”(非操作用户自写)喂入到代理LLM上下文。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata