playlet-douyin-feed
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在脚本
scripts/playlet_douyin_daily.py的fetch_playlet_data()运行时,通过https://redfox.hk/story/api/parseWork/queryPlayletMsgsPOST 拉取的抖音作品字段(如title、userName、coverUrl、url)会被直接读入并拼接到generate_html_report()生成的 HTML 中,属于外部/第三方来源的自由文本展示面。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata