playlet-douyin-feed

Warn

Audited by Snyk on Aug 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 在脚本 scripts/playlet_douyin_daily.pyfetch_playlet_data() 运行时,通过 https://redfox.hk/story/api/parseWork/queryPlayletMsgs POST 拉取的抖音作品字段(如 titleuserNamecoverUrlurl)会被直接读入并拼接到 generate_html_report() 生成的 HTML 中,属于外部/第三方来源的自由文本展示面。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 01:00 AM
Issues
1
Security Audit — snyk — playlet-douyin-feed