codebolt-api-access

Warn

Audited by Snyk on Feb 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill includes browser and crawler modules that navigate to arbitrary public URLs (e.g., codebolt.browser.goToPage + codebolt.browser.getMarkdown/getContent in references/browser.md and codebolt.crawler.goToPage in references/crawler.md), fetch untrusted third-party web page content, and expose that content for the agent to read and act on as part of its workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 24, 2026, 06:19 AM