peekaboo

Warn

Audited by Snyk on Mar 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly shows flows that open arbitrary webpages (e.g., peekaboo app launch "Safari" --open https://example.com) and then capture/analyze those windows (e.g., peekaboo image --app Safari --window-title "Dashboard" --analyze "Summarize KPIs"), which means the agent will ingest and act on untrusted public web content rendered in third‑party apps.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 3, 2026, 07:25 AM