trending-hub

Warn

Audited by Snyk on Jun 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). 运行时通过 scripts/fetch_hotspot.py 调用外部接口 https://redfox.hk/story/api/hotSpot/getListByPlatformWithKeyword 获取各平台热搜的 title/url 等文本,并将这些“非用户自选来源”的自由文本(热点标题)写入 output_compact/output_markdown,随后被智能体读入 LLM 上下文。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 12, 2026, 07:51 PM
Issues
1
Security Audit — snyk — trending-hub