xiaohongshu-write
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在 required workflow 中,脚本
scripts/search_xhs_work.py会把调用https://doubaoya.com/api/apis/xiaohongshu/search-work/call返回的data.items(包含标题/作者等文本)直接交给主 Agent 进行“复盘爆款(提炼流量密码)”并用于生成笔记,因此会摄入第三方/外部来源的自由文本内容而非仅使用第一方可信元数据。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata