office-oxide-mcp-server
Warn
Audited by Snyk on Jun 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The required runtime workflow can ingest outsider-authored free text when the user supplies an outsider document path to tools like
office_read(e.g., extractingmarkdown/text/chunksfrom a downloaded or third-party Office/PDF file), and that extracted prose is then fed into the agent’s LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata