dom-clone
Warn
Audited by Snyk on Aug 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In dom-clone’s runtime “Standalone” path, the workflow takes a user-provided <url>>, performs a browser recon (screenshots + interaction sweep), and extracts “real content” and computed styles via getComputedStyle()—meaning outsider-authored free text from that arbitrary web page is ingested at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata