gemma-gem-browser-ai

Warn

Audited by Snyk on Apr 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The offscreen agent explicitly calls the content-script tool read_page_content (content/tools/executor.ts reads document.body.innerText or selector textContent) and ingests page text/HTML from arbitrary web pages as part of its agent loop (agent/loop.ts), which can then drive tool calls like click_element and run_javascript — exposing it to untrusted third‑party content that can indirectly inject instructions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 8, 2026, 07:01 AM
Issues
2