docx
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow ingests and processes untrusted DOCX/XML content that may contain outsider-authored free text (e.g.,
scripts/comment.pyextractsword/document.xml/comment parts via_safe_extractwhen given an outsider-supplied.docx, then parses XML and embeds the provided comment text intocomments.xml).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata