yutori-browse

Warn

Audited by Snyk on Apr 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs using run_browsing_task with a user-provided start_url to browse and interact with arbitrary public websites, meaning the agent will fetch and interpret untrusted third-party web content that could contain malicious/indirect instructions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 11:16 PM
Issues
1