yichen-wecom-operations
Warn
Audited by Snyk on Aug 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The only runtime free text ingested from outside authorship is the user-supplied local Markdown path/content passed via
scripts/create_smartpage.py --source, where the script reads the file (discover_images: source.read_text) and then sends its contents into the first-partywecom-cli ... +smartpage_createcall.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata