textinxparse

Warn

Audited by Snyk on Aug 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). run.py 的 required runtime workflow 仅通过 user-supplied的 --task-context(本地临时JSON,含 user_intent/tool_call_reason)将用户原始表述传入 xparse-cli 的解析/读取定向流程,随后由 CLI 决定读取具体文档元素(源文本由服务在其侧获取,非 run.py 任意外部文本注入)。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 07:08 AM
Issues
1
Security Audit — snyk — textinxparse