webapp-testing
Warn
Audited by Snyk on Mar 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's workflow and examples (e.g., Reconnaissance-Then-Action and calls like page.goto/page.content in SKILL.md and examples) explicitly allow navigating to non-local URLs with user confirmation ("Garde-fous de sécurité — Avec confirmation explicite: toute autre URL — afficher l'URL complète et demander l'approbation"), meaning the agent can fetch and inspect arbitrary third-party pages and then derive selectors/actions from their DOM, which could enable indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata