pandoc

Warn

Audited by Snyk on Mar 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly instructs pulling and running the public pandoc/extra Docker image (SKILL.md and references/docker.md) and shows commands to download CSL/style files from raw.githubusercontent.com (references/snippets.md), which are open public third‑party resources the agent would fetch and consume at runtime and could therefore carry untrusted, user-provided content that can influence processing behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 2, 2026, 07:52 AM