pdf-image-text-extractor
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Skill “PDF和图片文字提取”通过运行时接收用户上传的图片/ PDF 文件,并在脚本中对 PDF 进行本地解析(scripts/pdf_text_extractor.py 读取页面文本块),把文件内的自由文本直接拼入 LLM 输出,因此存在由外部作者内容导致的间接提示注入暴露。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata