api-testing
Warn
Audited by Snyk on May 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The skill’s runtime workflow drives a browser session to a user-supplied URL (e.g.,
navigation go-to --url "https://app.example.com"), which can cause the LLM to ingest outsider-authored free text from fetched web page content (public web content) viacontent get-as-text/take-screenshotand related page-reading steps.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata