agent-browser

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill exposes the agent to untrusted third‑party content because the agent-browser CLI explicitly opens arbitrary public URLs via "agent-browser open " and then reads page content with commands like "snapshot" and "get text", allowing web or user-generated content to be ingested and potentially inject instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:14 PM