web-pentest

Warn

Audited by Snyk on Aug 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The pentest [URL] trigger leads to runtime ingestion of outsider-authored free text via scripts/recon-scan.sh, which curls the operator-supplied target URL (including robots.txt, sitemap.xml, and .well-known/security.txt) and writes the fetched contents to evidence files for the agent to analyze.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 22, 2026, 03:31 AM
Issues
1
Security Audit — snyk — web-pentest