domain
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Step 10a the workflow uses
agent-browserto open and interact with the outsider-authored USPTO Trademark Search UI athttps://tmsearch.uspto.gov/, then reads page text/screenshot results from the rendered page.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes commands and API usage to purchase domains (real-money actions). It shows the Vercel CLI purchase command ("vercel domains buy .com") and a Namecheap API call to create/register a domain using ApiUser/ApiKey/ClientIp. It also references required Namecheap API credentials and notes that running the buy step "charges real money" and must be confirmed. These are specific, built-in transaction actions (sending money to registrars), so this grants Direct Financial Execution authority.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata