glmocr-handwriting
Warn
Audited by Snyk on Jun 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). Outsider free text can enter the agent’s LLM context when the required runtime path uses
--file-urlto fetch a public URL and then ingests the API’s returnedmd_results/data.md_results(OCR text) into the output JSON fieldtext, which the agent may pass into the LLM; this OCR text originates from an outsider-authored document/page.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata