wecomcli-doc-manage
Warn
Audited by Snyk on Aug 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). 在“搜索文档”运行路径中,技能会基于用户提供的
keywords/过滤条件调用wecom-cli doc search,从而读取并处理(用于结果展示的)搜索匹配高亮片段等文档文本内容,但这是由技能“搜索”接口获取的企业文档数据而非任意第三方注入式自由文本源。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata