short-drama-produce

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). 生产运行路径 scripts/production_tool.py run_job -> _run_adapter -> scripts/provider_adapters.py 直接把 job 中的 prompt/parameters/lyrics(由外部用户文本间接形成的创作者确认内容)作为 provider 请求体字段发送给供应商,但该文本仅在 creator-first job 且经 prepare/confirm 闸门锁定后才被 LLM/模型读取,且不进行任意外部文本抓取或无选择投喂。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 03:46 PM
Issues
1
Security Audit — snyk — short-drama-produce