Browser Use
Warn
Audited by Snyk on Apr 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). This skill explicitly navigates and ingests arbitrary public URLs via commands like "browser-use open " and exposes page content through browser.html/state and autonomous agent tasks ("browser-use run") in SKILL.md, so untrusted third-party web content can be read and acted on by the agent.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata