academic-investigation

Warn

Audited by Snyk on Jun 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.78). 在“国际轨/Step 3 学生评价”与“国内轨/Step 6 多源验证”中,运行时会通过 international/xiaohongshu_client.py(小红书)或 domestic/wechat_search.py(微信公众号)把第三方平台的自由文本/帖子内容抓取并写入本地文件,再由 LLM 读取用于报告生成;这些均属于OUTSIDER(社交媒体/公众号等非操作用户撰写内容)→ LLM上下文的间接注入风险路径。

MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

  • Hidden Unicode characters detected (1 type(s) found)

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W021
MEDIUM

Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 4, 2026, 08:44 AM
Issues
2
Security Audit — snyk — academic-investigation