docx-generator

Warn

Audited by Snyk on Aug 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该 Skill 的运行时工作流在 create_simple_document/create_report 中直接将用户/调用方提供的 title/content/sections 这些自由文本写入 DOCX(以及 set_header_text/set_footer_text),因此外部作者可通过提供这些字段把“自由文本指令”喂给 LLM 侧(若该 Skill 被上层用 LLM 生成这些字段并传入)。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 07:45 PM
Issues
1
Security Audit — snyk — docx-generator