cv-generator

Warn

Audited by Snyk on Aug 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Skill reads and extracts free text from user-supplied LinkedIn URLs/pages, LinkedIn PDFs (including OCR), portfolio/personal-site URLs, uploaded resume files, and GitHub profile content during “Source Selection” and the corresponding “Data extraction rules,” so outsider-authored text can be ingested whenever the workflow fetches/parses those sources.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 5, 2026, 03:31 AM
Issues
1
Security Audit — snyk — cv-generator