qa
Warn
Audited by Snyk on Apr 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's browser mode and Phase 1/Phase 2 instructions explicitly direct the agent to open arbitrary URLs and interact with page DOM/console (see references/browser-mode.md "Navigate" using chromux open and Phase 1 "If URL or app provided: Navigate to the app"), so untrusted public web content will be read, interpreted, and used to drive clicks/actions and test decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata