feishu-doc-reader

Warn

Audited by Snyk on Jul 31, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill’s runtime path reads Feishu document contents via user-provided doc_token/block_id (e.g., ./scripts/read_doc.sh <doc_token> and ./scripts/get_blocks.sh <doc_token>) and returns the document’s text blocks, which are outsider-authored if the requester supplies a token to a document they do not own.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 31, 2026, 01:19 AM
Issues
1
Security Audit — snyk — feishu-doc-reader