bid-doc
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 该技能运行流程在 Step 1/2 直接解析用户上传的采购“技术规范文件”(doc/docx)与“评分标准”(文本或图片)的所有可读文本(python-docx、以及 Read 工具读图后提取),再用于生成最终文档与信息图,因此存在外部提交文本被 LLM/生成逻辑摄取的间接提示注入风险。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata