gzh-subscribe
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). 运行时通过
python3 scripts/account_works.py调用doubaoya.com的gongzhonghao-work-list/call,读取返回 JSON 中的data.items[*].title等字段并由主 Agent 渲染成 Markdown 表(外部文本来自 doubaoya API 的公众号文章标题/元数据,而不是用户提供的直接提示注入文本);因此不存在“先选择具体条目前就摄入攻击者可控自由文本”的队列/流式注入路径。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata