xiaohongshu-comment
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). 运行时会调用
doubaoya.com的公开 APIPOST /api/apis/xiaohongshu/comments/call,其返回的data.items[].content(小红书评论正文)会被脚本 JSON 打到 stdout 并进入后续 LLM 处理;这些评论属于小红书“非操作用户”作者的免费文本。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata