view-pdf
Warn
Audited by Snyk on Mar 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly accepts and opens arbitrary HTTPS PDF URLs (see "display_pdf" url param and "Supported Sources: Any direct HTTPS PDF URL") and uses
get_textto read PDF content as part of its annotation/decision workflow, so untrusted public PDFs could inject instructions that influence tool actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata