stitch::extract-static-html
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/snapshot.ts, the workflow uses Puppeteer to navigate to a user-supplied--urland then ingests outsider-authored free text from the loaded page (e.g., viapage.goto()and subsequentdocument.documentElement.outerHTMLextraction after inline/fetch operations).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata