xiaohongshu-realtime-search

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). 运行时通过 search_xhs_work.py 向外部 Redfox API(https://redfox.hk/story/api/xhs/ability/searchWork)POST 查询并将返回的作品字段(如 noteTitleauthorNamenoteUrl 等)作为可读文本进入后续 Step 3 的 Markdown 表格,从而把“外部平台/第三方接口返回内容(非用户自选引入的文本)”喂入 LLM 上下文。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 05:15 AM
Issues
1
Security Audit — snyk — xiaohongshu-realtime-search