weibo-hot-scraper

Warn

Audited by Snyk on Aug 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该技能会打开并抓取微博热搜搜索结果页(https://s.weibo.com/top/summary?cate=realtimehot 与后续拼接的 https://s.weibo.com + t.href &page=…),然后从页面 DOM 读取热搜标题/链接及每条帖子“完整原文+转发内容+作者名”等自由文本并落盘为 Markdown,因此外部用户可通过在微博上发布内容来注入毒化文本。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 6, 2026, 03:42 AM
Issues
1
Security Audit — snyk — weibo-hot-scraper