xhs-portfolio-search
Warn
Audited by Snyk on Jul 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). 运行时会调用
scripts/fetch_xhs_user_works.py向外部服务https://redfox.hk/story/api/xhs/ability/userWorkList获取小红书博主作品数据,并将返回的noteTitle/authorName/bio等字段作为可读文本进入代理上下文;这些内容属于非操作用户选择引入的第三方/外部来源(小红书内容经由 RedFox API 间接进入)。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata