academic-investigation
Warn
Audited by Snyk on Jun 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.78). 在“国际轨/Step 3 学生评价”与“国内轨/Step 6 多源验证”中,运行时会通过
international/xiaohongshu_client.py(小红书)或domestic/wechat_search.py(微信公众号)把第三方平台的自由文本/帖子内容抓取并写入本地文件,再由 LLM 读取用于报告生成;这些均属于OUTSIDER(社交媒体/公众号等非操作用户撰写内容)→ LLM上下文的间接注入风险路径。
MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
- Hidden Unicode characters detected (1 type(s) found)
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W021
MEDIUMHidden or invisible Unicode characters detected (potential obfuscation or prompt injection).
Audit Metadata