web-fetch
Warn
Audited by Snyk on Aug 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Required runtime workflow lets the user-provided URL drive a runtime
curl -sL "$URL"/bun fetch.ts "<url>"fetch, then parses and converts the fetched outsider-authored page text into markdown (free text ingestion occurs before any site-specific selection is guaranteed to match).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata