cdp
Fail
Audited by Snyk on Jun 23, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The skill provides explicit remote-control and automation primitives (an externally bound CDP proxy, Raw CDP with Runtime.evaluate, screenshot/data extraction, and automated Google sign-in using stored credentials and App Passwords with instructions to “bypass anti-automation detection”), which are dual‑use but clearly enable credential theft, token capture, and remote browser compromise if exposed or abused.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The skill’s runtime path includes
charly check cdp openwhich fetches arbitrary outsider-authored web page content via Chrome’s HTTP navigation (/json/new?url=...), and then ingests that page’s readable text/HTML back into the LLM context through commands likecdp text/cdp html/cdp eval(e.g.,document.body.innerText,outerHTML).
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata