gzh-astock-top
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 该技能运行时会向 doubaoya.com 先用用户提供的
--keyword进行“账号发现”(POSTgongzhonghao-search-user/call),并读取返回数据中包含的账号/内容字段随后继续调用“当日发文/爆文”等接口;因此攻击者可在keyword这个外部自由文本输入路径上诱导服务返回其投毒的自由文本供脚本解析与输出。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata