byted-viking-aisearch-feishu
Warn
Audited by Snyk on Jul 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Required runtime path
fetch_raw_content()→get_docx_raw_content()/get_doc_raw_content()/fetch_sheet_content()/fetch_bitable_content()/get_wiki_node()/list_wiki_space_nodes()calls Feishu APIs and ingests outsider-authored document/wiki text (e.g., docx raw_content, sheet cell values, wiki node content) into the returnedcontentfield that the agent would then place into the LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata