markitdown-cli
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md 的 Step 1/4/9 明确要求将用户输入的任意免费文本(尤其是用户提供的
http(s)://…或 stdin 管道内容)用于构造并触发markitdown的实际解析/GET(见“HTTP URL 走真实 GET/SSRF 风险”与“不要把任意 URL 直接喂给…”),从而使该 free text 进入运行时的内容抽取流程。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata