nv-reason-cxr

Warn

Audited by Snyk on Jul 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). The required workflow can call the public Hugging Face Space backend (--backend hf-space-api), where the remote Gradio streaming response is fetched at runtime and its text is returned as response_text (i.e., remote, outsider-authored free text from https://nvidia-nv-reason-cxr.hf.space via _http_fetch/_stream_hf_space_response).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 07:15 PM
Issues
1
Security Audit — snyk — nv-reason-cxr