chrome-cdp

Warn

Audited by Snyk on Aug 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The runtime reads outsider-authored free text only if the caller supplies it via CLI args into the required page-monitoring/evaluation workflow (e.g., scripts/cdp.mjs eval <target> <expr>, html <target> [selector], nav <target> <url>, type <target> <text>, and evalraw <target> <method> [json]), and there is no built-in ingestion of any external monitored feed/queue content.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Issues
1
Security Audit — snyk — chrome-cdp