xiaohongshu-realtime-search
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). 运行时通过
search_xhs_work.py向外部 Redfox API(https://redfox.hk/story/api/xhs/ability/searchWork)POST 查询并将返回的作品字段(如noteTitle、authorName、noteUrl等)作为可读文本进入后续 Step 3 的 Markdown 表格,从而把“外部平台/第三方接口返回内容(非用户自选引入的文本)”喂入 LLM 上下文。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata