jkvideo-bilibili-react-native

Warn

Audited by Snyk on Mar 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill directly ingests untrusted, user-generated content—e.g., fetching danmaku XML from /x/v1/dm/list.so (hooks/useDanmaku.ts), receiving live chat over wss://broadcastlv.chat.bilibili.com/sub (hooks/useLiveDanmaku.ts), and loading public Bilibili pages in a WebView fallback (components/VideoPlayer.tsx)—all of which are runtime third‑party sources the agent parses/displays and could influence behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 25, 2026, 01:41 AM
Issues
1