burp-zap-hardened
Warn
Audited by Snyk on Apr 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md instructs the agent to call the MCP tool get_proxy_history and parse request/response bodies (e.g., response.body, extract_ids, check_sensitive_data) from Burp's proxy history—i.e., arbitrary external HTTP responses captured by Burp—which are untrusted third-party content the agent reads and uses to drive analysis and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata