claude-chrome
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). Yes — the Claude Code Chrome integration explicitly navigates and reads arbitrary web pages via the Chrome extension (e.g., "Go to example.com and read the headline"), so the agent ingests untrusted public web content that could carry indirect prompt injection.
Audit Metadata