feishu-permission-setup

Warn

Audited by Snyk on Mar 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill's runtime script scripts/feishu_scope_publish.js uses Playwright to navigate to and scrape live pages on the public Feishu site (e.g., https://open.feishu.cn/app/${appId}/baseinfo and dialogs/rows it reads like dialog.textContent()/row.textContent()), and it parses that page text to decide actions (add/publish scopes, click buttons), so third-party page content can directly influence tool behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 15, 2026, 04:38 AM
Issues
1