paper-deep-reading
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/fetch.py→resolve_europepmc()/resolve_preprint()the workflow fetches outsider-authored paper metadata/abstract and then downloads and parses the PDF bytes from user-supplied arXiv/DOI/PMCID/PMID URLs, making the paper text (including any adversarial content inside the PDF) directly readable by the runtime LLM steps that “teach/judge/write” the note.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata