xiaohongshu-growth

Warn

Audited by Snyk on Apr 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). This skill's SKILL.md explicitly instructs the pipeline to call the brave-search skill in "选题与热点研究" to fetch open web / social content (e.g., 小红书爆火文章, 竞品分析), which agents ingest and use to drive recommendations, content creation, and publishing decisions, so untrusted third‑party content could indirectly inject instructions that change behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 12:45 PM
Issues
1