playlet-douyin-feed

Warn

Audited by Snyk on Jun 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). 运行时 LLM 上下文会包含 API 返回的作品字段(如 titleuserNameurlcoverUrl)并被拼接进生成的 HTML/终端摘要;这些字段来自红狐Hub/抖音的第三方内容(外部作者的标题/用户名/链接),属于“公共平台内容/他人创作的文本”经由脚本读取后进入可读文本上下文。

MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

  • Hidden Unicode characters detected (1 type(s) found)

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W021
MEDIUM

Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 07:56 AM
Issues
2
Security Audit — snyk — playlet-douyin-feed