recon-workbench
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly runs web probes that navigate to arbitrary URLs and ingest their HAR/trace output (see assets/template/probes/catalog.json entries web.playwright_trace and web.playwright_har_capture and the scripts assets/template/scripts/probes/web_playwright_trace.mjs and web_playwright_har.mjs), and SKILL.md / references/skill_web_app_interrogate.md require the agent to summarize those artifacts and use them to plan/escalate, so untrusted third‑party web content can be read and materially influence decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata