extract-html
Fail
Audited by Snyk on Mar 17, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt's example and options instruct passing an API key directly on the command line (--vision-api-key "sk-..."), which would require embedding secret values verbatim in generated commands or code, an insecure pattern.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill can fetch remote images referenced by input HTML (extract_html/media.py -> load_image_bytes when fetch_remote_media=True and the CLI option --fetch-remote-media) and then OCR and include that extracted text plus the cleaned HTML itself into the prompt sent to the LLM (extract_html/pipeline.py -> media_json and extract_html/schematron.py which injects CLEANED_HTML and MEDIA_TEXT into the model prompt), meaning untrusted third‑party content can be ingested and materially influence model behavior.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata