global-ai-news-brief
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在 Required workflow 中,用户输入的关键词会被直接用于调用
scripts/fetch_all.py向https://redfox.hk的 11 个搜索接口 POST 请求并读取返回的items[].title/content/author/...作为后续 AI 分析与 HTML 报告渲染的文本,因此外部作者(平台内容作者/页面作者)可通过其内容在运行时进入模型可读上下文。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata