byted-seedream-image-generate

Warn

Audited by Snyk on Jul 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The runtime path scripts/seedream_image_generate.py ingests outsider-provided --prompt/prompt text directly into the API request body field "prompt" via _build_request_body()_call_image_api() (and optionally enables "tools": [{"type": "web_search"}] on 5.0), but this workflow does not appear to fetch arbitrary outsider-authored free text unless it is explicitly provided by the caller as the prompt (text the user submits).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 30, 2026, 03:19 PM
Issues
1
Security Audit — snyk — byted-seedream-image-generate