webclaw
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs users to run 'npx create-webclaw' and 'npx @webclaw/mcp'. These commands fetch and execute code from the npm registry at runtime. This poses a significant risk as the code is executed without prior manual verification of the package integrity or source by the user.
- [EXTERNAL_DOWNLOADS]: The skill documentation specifies that its backend server is fetched from external servers (npm) on the first launch and cached locally.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for ingesting untrusted data from any web URL provided to tools like 'scrape', 'crawl', or 'extract'.
- Ingestion points: Untrusted data enters the agent context through the 'url' parameter in all scraping and crawling tools (SKILL.md).
- Boundary markers: The skill instructions do not include boundary markers or delimiters to warn the agent against following instructions embedded in the fetched content.
- Capability inventory: The skill possesses extensive network capabilities and the ability to process content via LLMs (SKILL.md).
- Sanitization: Content is converted to Markdown or JSON but is not sanitized to remove potential prompt injection payloads from the source material.
- [COMMAND_EXECUTION]: The skill relies on shell-level installation and execution commands via 'npx'.
Recommendations
- AI detected serious security threats
Audit Metadata