playlet-bili-feed
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). 运行时会调用
scripts/fetch_playlet_feed.py向doubaoya.com的bilibili-playlet-feed接口请求,并把返回信封里的data.items(含title等文本)直接print到 stdout,随后进入后续“渲染爆款表格/聚类日报”的 LLM 上下文;该文本来源于外部抓取/聚合的 B 站内容(非操作用户自写)。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata