wechat-10w-hot

Warn

Audited by Snyk on Aug 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该工作流在运行时通过 scripts/fetch_10w_hot.pyhttps://doubaoya.com/api/apis/gongzhonghao/category-time-hot/call 发起固定入参的 POST 请求并读取其返回 JSON 中的 data.items(含 title/accountName/readCount)用于生成表格,属于外部服务返回文本的直接摄取;虽然调用参数由闭集分类控制,但返回内容仍可能包含由第三方来源作者产生的免费文本。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 18, 2026, 11:42 AM
Issues
1
Security Audit — snyk — wechat-10w-hot