xiaohongshu-lowtop
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在用户触发查询后,运行时会通过 scripts/fetch_explosive_articles.py 调用外部 API(https://redfox.hk/.../getXhsCozeSkillDataLowFans)获取小红书笔记字段(title/desc/userName/链接等),并将其中可读的自由文本原样写入 md 输出与生成 HTML(generate_html_from_template / get_article_html),因此来源于平台用户内容的“免费文本”(如笔记标题/描述/用户名)会被 LLM/系统纳入口径的数据管道处理。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata