automating-the-browser
Warn
Audited by Snyk on Aug 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). SKILL.md describes
crawlberg interact <url> --actionsdriving a headless browser to the user-supplied URL and then capturing the resulting page DOM (interaction.final_html/scrape), so outsider-authored free text on arbitrary pages could be ingested at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata