pandoc
Warn
Audited by Snyk on Mar 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly instructs pulling and running the public pandoc/extra Docker image (SKILL.md and references/docker.md) and shows commands to download CSL/style files from raw.githubusercontent.com (references/snippets.md), which are open public third‑party resources the agent would fetch and consume at runtime and could therefore carry untrusted, user-provided content that can influence processing behavior.
Audit Metadata