browser-control
Warn
Audited by Snyk on Jun 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). At runtime, the skill reads outsider-authored page text/DOM from the user’s real Chrome session via AppleScript/
/eval(e.g.,document.body.innerText/ DOM-to-Markdown extraction inmodules/dom-extraction.mdandmodules/applescript-commands.md, and CDP/evalinmodules/cdp-proxy-api.md), which then gets fed into the agent’s LLM context as extracted content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata