douyin-daily-hot

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). 运行时通过 scripts/fetch_daily_hot.py 调用 https://doubaoya.com/.../douyin-likes-rank/call 获取的 envelope.data.items(含 title/accountName/workUrl)会作为可读 JSON 文本被打印并进入主 Agent 上下文;这些内容来自外部服务/网页聚合方而非操作用户自有文本。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 05:47 PM
Issues
1
Security Audit — snyk — douyin-daily-hot