wx-mp-hunter

Warn

Audited by Snyk on Aug 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In wx_mp_hunter.ts, the fetch <url> and the专题页抓取流程 both cause the runtime to HTTP GET and HTML-parse arbitrary mp.weixin.qq.com article content into content_text/content_markdown (via cmdFetchmpFetchloadHtml + #js_content extraction), so an outsider can submit a free-text URL which the workflow will directly ingest.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 14, 2026, 01:22 AM
Issues
1
Security Audit — snyk — wx-mp-hunter