playwright-skill
Warn
Audited by Snyk on Jun 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). At runtime,
bin/contextrunsplaywright-cli run-codeto read live page HTML/URL/title and injectedwindow.__capturedConsole/window.__capturedRequests, thenResponseBuilderincludes these strings/arrays in the LLM-visibleTrimmedResponseand caches them—so any outsider-authored content on the visited site (including attacker-controlled text in DOM/console/network) can flow into the agent context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata