aut-sci-ppt

Warn

Audited by Snyk on Aug 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In the paper_workflow runtime path, the agent builds outline_text from outsider-authored Markdown (user-edited PDF outline file) and then ingests it into PPTAgent.generate(ppt_text, ...) via parse_outline_to_ppt_input()_outline_to_ppt_text()PPTAgentTextParser.parse(), so free text is read without selecting a specific item first.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 3, 2026, 02:22 PM
Issues
1
Security Audit — snyk — aut-sci-ppt