lighthouse-runner
Warn
Audited by Snyk on Jun 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required workflow ingests outsider-authored free text when the operating user supplies an arbitrary
http(s)://...URL (or a local HTML file that loads external resources): Lighthouse/Chromium fetches and parses the page’s DOM/text and then the skill includes outsider-derived strings likeaudit.title,audit.description, andaudit.displayValuein the generated text/JSON output that is fed into the agent’s LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata