trending-hub-top10

Warn

Audited by Snyk on Jun 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). 运行时通过 scripts/fetch_hotspot.py 调用外部 Redfox API 获取各平台热搜标题(hotspots[].titlehotspots[].url),这些标题/链接来自非操作用户选择引入的第三方平台内容,随后被写入 structured_report.json 并在 scripts/generate_html_report.py 生成HTML/并由智能体分析进入LLM上下文。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 12, 2026, 07:51 PM
Issues
1
Security Audit — snyk — trending-hub-top10