platform-docs-get
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime path, the extraction playbook routes a user-supplied
--urlinto Playwright and reads renderedinnerText/textContentfrom that page (including shadow-DOM) before grounding, so outsider-authored free text can be ingested whenever a caller can cause the workflow to fetch an attacker-controlled page.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata