next-dev-loop

Warn

Audited by Snyk on Aug 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In the required workflow, the agent calls the first-party Next.js dev endpoint /_next/mcp (including tools/list and get_compilation_issues) and drives the user’s target page via agent-browser open <url> while using a browser session, so outsider-authored free text can be ingested from the user-controlled page/its runtime content and from any developer-queue data the app surfaces into that endpoint.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 11, 2026, 09:44 PM
Issues
1
Security Audit — snyk — next-dev-loop