google-ai-search

Warn

Audited by Snyk on Jul 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In scripts/google-ai-search.ts, the runtime page submits the outsider-provided query into Google and then ingests Google’s AI Overview HTML either from network response bodies to https://www.google.com/async/folif? or from the data-subtree="aimc" DOM, so free-text from the skill invoker can influence what is fetched/returned.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 30, 2026, 01:44 PM
Issues
1
Security Audit — snyk — google-ai-search