xiaohongshu-dailytop

Warn

Audited by Snyk on Aug 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 在运行时,当用户触发查询时,技能会把由第三方平台用户撰写的笔记标题/描述等文本从红狐 API 接口 https://redfox.hk/story/api/cozeSkill/getXhsCozeSkillDataOne 的返回中取回并直接用于输出/HTML 渲染(scripts/xhs_daily_fetcher.pyscripts/gen_xhs_html.py 的数据字段清洗与模板注入路径),因此存在间接提示注入风险。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 09:46 AM
Issues
1
Security Audit — snyk — xiaohongshu-dailytop