xiaohongshu-comment
Warn
Audited by Snyk on Jun 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). 该技能在 Step 2/3 通过
xiaohongshu_comment_search.py调用 Redfox API 获取小红书“评论内容(content/commentText)”后,将这些评论文本直接用于对话展示与 AI 总结(属于第三方/外部用户在平台上撰写的自由文本,经由 API 返回后进入 LLM 上下文)。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata