arxiv-reading
Warn
Audited by Snyk on Jul 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider-authored free text can enter the LLM via the runtime web fetch of arXiv/ar5iv HTML (public web content) when
arxiv2mdfails, e.g., “WebFetch on https://ar5iv.org/abs/” which returns rendered paper text/HTML that is then converted to Markdown and fed to the agent.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata