download-webpage-as-pdf

Warn

Audited by Snyk on Aug 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Outsider-authored free text is ingested at runtime when the workflow runs agent-browser open <URL> and then agent-browser eval(...) over the resulting page DOM (including any user-controlled HTML/text on that page) to strip lazy-load attributes, scroll, and await image decoding before generating /tmp/page.pdf.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 6, 2026, 03:56 PM
Issues
1
Security Audit — snyk — download-webpage-as-pdf