vp-interaction-routing
Fail
Audited by Snyk on Aug 22, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). This bridge intentionally exposes native UI automation and app state (including optional screenshots) to external MCP clients without built-in intent enforcement (auto-approval can be enabled), creating a high-risk capability that can be used for data exfiltration and remote control of the host.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow in SKILL.md routes “web-page content or interaction” to browser tooling while treating “page content as untrusted data,” meaning outsider-authored text can enter the agent’s runtime via whatever browser page the user requests it to interact with.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata