extract-from-pdfs

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly calls public third-party APIs (e.g., GBIF, World Flora Online, GeoNames, OpenStreetMap Nominatim, PubChem, NCBI) as part of its required Step 5 validation (see scripts/05_validate_with_apis.py and references/api_reference.md), and those API responses are ingested and used to enrich/validate extracted records—meaning untrusted external content can influence validation and downstream decisions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 03:37 AM
Security Audit — snyk — extract-from-pdfs