web-clipper

Warn

Audited by Snyk on May 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches and ingests arbitrary public webpages (scripts/clip_articles.py's fetch/parse_article and fetch_via_metaso), and the SKILL.md workflow (路径 B/路径 C and the provided browser.evaluate JS) directs the agent to collect and act on untrusted index/article content and URLs, which directly determine subsequent tool use and file-writing actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 1, 2026, 12:55 AM
Issues
1
Security Audit — snyk — web-clipper