mathpix
Warn
Audited by Snyk on Jun 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow sends user-supplied
srcURLs (e.g.,https://mathpix.com/examples/equation.png) to Mathpix, which fetches that external page/image at runtime and returns extracted text/LaTeX into the agent’s LLM context—i.e., public web content from an outsider source via thesrcfield.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata