dingtalk-event
Warn
Audited by Snyk on Jul 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). 在 required workflow 中运行
dws event consume ... -f ndjson,其运行时会把来自钉钉个人 IM 事件的“消息正文/发送人/表情文本”等 outsider-authored 自然语言内容逐行写到 stdout(stdout 被 LLM 读取进入上下文),因此存在间接提示注入风险。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata