browser-trace
Warn
Audited by Snyk on Jul 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Yes: the required runtime workflow streams the traced browser’s CDP firehose (including arbitrary page content like DOM/console text) into local NDJSON/HTML files (
browse cdp ...→cdp/raw.ndjson, andbrowse get html body→dom/<ts>.html), which are then available for later LLM context ingestion; this is outsider-authored free text originating from whatever websites/pages the user’s automation visits.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata