paper-figures
Warn
Audited by Snyk on Aug 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). SKILL.md/scripts/extract-figures.py ingest text only from the user-supplied local PDF at runtime (page.get_text("blocks") and caption regex matching) and do not include any outsider free-text submission/feed that the agent monitors without a specific PDF input.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata