byted-seedream-image-generate
Warn
Audited by Snyk on Apr 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill accepts arbitrary external resource URLs for reference images (--image / --images) and explicitly enables a 5.0-lite "web_search" tool (see SKILL.md usage and scripts/seedream_image_generate.py where task["tools"] = [{"type":"web_search"}]), which causes the model/service to fetch and use open/public third‑party web content that can influence generation behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata