regex-vs-llm-structured-text
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow ingests first-party “content: str” passed into
process_document, runs regex parsing and then sends that same input text into the LLM viavalidate_with_llmonly for low-confidence items, so outsider-authored text would be exposed if the caller supplies it as the document “content.”
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata