csv-to-latex-book

Warn

Audited by Snyk on Jul 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). The required workflow ingests the user-supplied practice-test CSV and renders its free-text fields (question text, option text, per-option explanations, overall explanations, and domain) directly into the generated LaTeX context via parse_csv() → render_question()/titlepage() → tex() escaping, so any outsider-authored CSV content would become LLM-readable prose at runtime.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 12, 2026, 07:50 AM
Issues
1
Security Audit — snyk — csv-to-latex-book