platform-docs-get

Warn

Audited by Snyk on Aug 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In the required runtime path, the extraction playbook routes a user-supplied --url into Playwright and reads rendered innerText/textContent from that page (including shadow-DOM) before grounding, so outsider-authored free text can be ingested whenever a caller can cause the workflow to fetch an attacker-controlled page.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 1, 2026, 09:43 AM
Issues
1
Security Audit — snyk — platform-docs-get