chrome-devtools
Fail
Audited by Snyk on Apr 11, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill includes examples that pass passwords/credentials directly on the command line (e.g., node fill.js --selector "#password" --value "secret"), which requires the agent to include secret values verbatim in generated commands and is therefore insecure.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill’s workflow and scripts (see SKILL.md and files like scripts/navigate.js, evaluate.js, snapshot.js, screenshot.js, network.js, and console.js) explicitly accept arbitrary --url targets and extract/evaluate page DOM, console output, network responses, and run page JS, meaning it fetches untrusted public web content and uses that content to drive selector discovery, clicks, form fills, and evaluated results that can materially influence subsequent tool actions.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.80). The skill instructs running installation scripts and explicit sudo apt-get commands (e.g., ImageMagick and system libraries via install-deps.sh), which modify system state and require elevated privileges, so it risks compromising the host.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata