quarterly-work-dashboard
Warn
Audited by Snyk on Jul 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). 技能在运行时会通过飞书模块把飞书文档内容/聊天消息的正文(外部作者的 free text)读取为字符串并写入 summary.json/index.html(例如
scripts/generate_feishu_quarterly_dashboard.py读取 markdown 文本到documents[].excerpt与消息content_excerpt),这类文本随后会进入后续“总面板”LLM上下文用于生成网页内容。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata