cdp

Fail

Audited by Snyk on Jun 23, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The skill provides explicit remote-control and automation primitives (an externally bound CDP proxy, Raw CDP with Runtime.evaluate, screenshot/data extraction, and automated Google sign-in using stored credentials and App Passwords with instructions to “bypass anti-automation detection”), which are dual‑use but clearly enable credential theft, token capture, and remote browser compromise if exposed or abused.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). The skill’s runtime path includes charly check cdp open which fetches arbitrary outsider-authored web page content via Chrome’s HTTP navigation (/json/new?url=...), and then ingests that page’s readable text/HTML back into the LLM context through commands like cdp text / cdp html / cdp eval (e.g., document.body.innerText, outerHTML).

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 23, 2026, 11:39 AM
Issues
2