xiaohongshu-hot-notes
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 运行时会对用户提炼的关键词调用
scripts/fetch_hot_notes.py,并读取POST https://doubaoya.com/api/apis/xiaohongshu/search-note/call返回的data.items中包含的笔记文本字段来生成榜单(外部内容可被发布并通过关键词检索进入 LLM 处理链)。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata