csv-to-latex-book
Warn
Audited by Snyk on Jul 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow ingests the user-supplied practice-test CSV and renders its free-text fields (question text, option text, per-option explanations, overall explanations, and domain) directly into the generated LaTeX context via
parse_csv()→render_question()/titlepage()→tex()escaping, so any outsider-authored CSV content would become LLM-readable prose at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata