literature-search
Warn
Audited by Snyk on Jun 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider-authored free text can enter the LLM context via the
fulltext/resolvepath:tools/lit/sources/arxiv.pyfetches arXiv HTML/LaTeX/PDF content from the public web at runtime (e.g.,get_bytes(.../e-print/...)andlatex_sections()), and the agent then reads that extracted text (or the generatedarxiv_*.txtfile) as prose for downstream LLM use.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata