webfetch-plus

Warn

Audited by Snyk on May 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches arbitrary public URLs (SKILL.md shows piping a URL into bin/wfp.sh and runtime/webfetch-plus.mjs calls page.goto(options.url)), extracts and writes the page text/metadata, and the required failure workflow/metadata (attempt_*.metadata.json and the SKILL.md retry steps) uses the page-derived "suggestion" to adjust retry parameters, so untrusted third‑party page content can directly influence tool behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 20, 2026, 05:35 AM
Issues
2
Security Audit — snyk — webfetch-plus