pdf-extraction
Warn
Audited by Snyk on Jul 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill’s workflow is about extracting readable text from a user-provided PDF via pdfplumber (e.g.,
page.extract_text()/page.extract_tables()), so at runtime the LLM context could include free text originating from an outsider-authored PDF document.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata