douyin-works-crawler

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). 运行时通过 fetch_user_works.pydoubaoya.com 的公开接口拉取 envelope.data.profileenvelope.data.items[].title 等文本字段,这些内容来自第三方(doubaoya.com/抖音账号作品数据)而非操作用户选择的自有文本,随后被打印到 stdout 并进入主 Agent 的 LLM 上下文。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 05:47 PM
Issues
1
Security Audit — snyk — douyin-works-crawler