bid-doc

Warn

Audited by Snyk on Aug 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该技能运行流程在 Step 1/2 直接解析用户上传的采购“技术规范文件”(doc/docx)与“评分标准”(文本或图片)的所有可读文本(python-docx、以及 Read 工具读图后提取),再用于生成最终文档与信息图,因此存在外部提交文本被 LLM/生成逻辑摄取的间接提示注入风险。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 14, 2026, 03:59 PM
Issues
1
Security Audit — snyk — bid-doc