douban-skill

Warn

Audited by Snyk on Apr 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill fetches and ingests user-generated content from public Douban endpoints (frodo.douban.com via scripts/douban-frodo-export.py and the public RSS feed https://www.douban.com/feed/people//interests via scripts/douban-rss-sync.mjs) and the code parses titles/comments to drive pagination, categorization, and file-write decisions, so untrusted third-party content can materially influence runtime behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 5, 2026, 03:21 PM
Issues
1