playlet-bili-feed

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). 运行时会调用 scripts/fetch_playlet_feed.pydoubaoya.combilibili-playlet-feed 接口请求,并把返回信封里的 data.items(含 title 等文本)直接 print 到 stdout,随后进入后续“渲染爆款表格/聚类日报”的 LLM 上下文;该文本来源于外部抓取/聚合的 B 站内容(非操作用户自写)。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 05:47 PM
Issues
1
Security Audit — snyk — playlet-bili-feed