true-dom-tester
Fail
Audited by Snyk on Jun 19, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill generates test code that embeds literal input values (e.g., page.fill('password123')), so if real credentials or API keys are used for testing they would be included verbatim in the LLM's output, creating an exfiltration risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill’s runtime workflow ingests accessibility-tree text produced from
playwright-cli open <url>+playwright-cli snapshot; if<url>is an outsider-controlled public web page (or any page containing outsider-authored text), that page’s rendered accessibility text is fed into the agent/LLM context for test generation (indirect prompt injection risk).
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.70). The prompt explicitly recommends using "Firecrawl" to bypass bot protection (Cloudflare, DataDome etc.), i.e. to circumvent security mechanisms — which is a security-risk instruction — even though it does not request sudo, system-file modification, or user creation.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata