save-report
Warn
Audited by Snyk on Jul 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). Runtime path: the skill reads the user-supplied medical report image via
mcp__4_5v_mcp__analyze_imageand then uses the extracted text (from the image) as LLM context; since the image content is not authored by the operating user, it can contain outsider-provided free text (e.g., printed/embedded instructions) that the LLM ingests.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata