confluence-browser-fetch

Warn

Audited by Snyk on May 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). This skill explicitly launches a browser and fetches arbitrary Confluence pages, rendered browser HTML, storage/view HTML, and attachments from a user-specified Atlassian site (see scripts/confluence-browser-fetch.js: fetchText/fetchJson saving page.browser.html, page.view.html, attachments, and SKILL.md which instructs ingesting raw/confluence/... into an LLM wiki), meaning untrusted, user-generated wiki content is ingested at runtime and could influence subsequent agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 19, 2026, 12:15 AM
Issues
1
Security Audit — snyk — confluence-browser-fetch