websearch
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides the agent with a local CLI tool,
free-search, to perform web operations. This allows the agent to execute shell commands for searching, fetching page content, and performing research tasks. The instructions also include diagnostic commands using theuvtool to run the search MCP backend. - [INDIRECT_PROMPT_INJECTION]: The skill exposes the agent to indirect prompt injection by enabling it to ingest and process content from arbitrary external websites. Malicious instructions embedded in fetched web pages could potentially influence the agent's behavior during a session.
- Ingestion points: Web content is retrieved and processed through the
free-search fetch,free-search search, andfree-search researchcommands defined inSKILL.md. - Boundary markers: The skill does not define any explicit delimiters or instructions to treat external web content as untrusted data.
- Capability inventory: The agent has the capability to execute local shell commands (
free-search,uv) and access the internet. - Sanitization: There are no mentions of sanitization, filtering, or validation of the content retrieved from the web before it is processed by the agent.
Audit Metadata