paper-to-gpui

Warn

Audited by Snyk on Aug 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). references to the currently open Paper Desktop file are read via the Paper MCP toolchain (e.g., get_basic_info/get_selection/get_node_info/get_jsx/get_computed_styles/get_screenshot) from http://127.0.0.1:29979/mcp, so outsider-authored free text inside the Paper document can be ingested at runtime.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 16, 2026, 12:59 AM
Issues
1
Security Audit — snyk — paper-to-gpui