soia-cwork-feishu-doc-git-sync

Warn

Audited by Snyk on Aug 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 飞书知识库同解析同步在运行时会直接从飞书侧读取文档/Sheet 内容并喂给 LLM 进行转换:scripts/sync_feishu_wiki.py 调用 fetch_doc(...)->raw_contentdocs +fetch ... --doc-format markdown --format json)以及在启用后调用 fetch_sheet_csv(...)sheets +csv-get)把正文/表格快照内容进入 normalize_content(...)markdown_table_from_csv(...) 等渲染逻辑。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 6, 2026, 08:45 AM
Issues
1
Security Audit — snyk — soia-cwork-feishu-doc-git-sync