xhs-portfolio-search

Warn

Audited by Snyk on Jul 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). 运行时会调用 scripts/fetch_xhs_user_works.py 向外部服务 https://redfox.hk/story/api/xhs/ability/userWorkList 获取小红书博主作品数据,并将返回的 noteTitle/authorName/bio 等字段作为可读文本进入代理上下文;这些内容属于非操作用户选择引入的第三方/外部来源(小红书内容经由 RedFox API 间接进入)。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 3, 2026, 02:06 AM
Issues
1
Security Audit — snyk — xhs-portfolio-search