gzh-astock-top

Warn

Audited by Snyk on Aug 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该技能运行时会向 doubaoya.com 先用用户提供的 --keyword 进行“账号发现”(POST gongzhonghao-search-user/call),并读取返回数据中包含的账号/内容字段随后继续调用“当日发文/爆文”等接口;因此攻击者可在 keyword 这个外部自由文本输入路径上诱导服务返回其投毒的自由文本供脚本解析与输出。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 14, 2026, 03:21 AM
Issues
1
Security Audit — snyk — gzh-astock-top