image-parser

Warn

Audited by Snyk on Mar 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill sends user-supplied images to the SoMark API (SOMARK_SYNC_URL: https://somark.tech/api/v1/extract/acc_sync) and ingests the returned JSON/markdown outputs which the agent is instructed to read and use for field extraction and answers (see SKILL.md and image_parser.py), so untrusted/user-generated parsed text from third-party processing could influence downstream decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 04:49 PM
Issues
1