weibo-hot-search
Warn
Audited by Snyk on Jul 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Runtime path:
scripts/fetch_weibo_hot.pycalls a public third-party API (https://redfox.hk/.../hotSearch) and ingests outsider-provided free text fields liketitleinto the JSONitems, which the agent then uses to generate the “灵感分析总结” in the LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata