web-scraping-automation

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides implementation patterns that use subprocess.run to execute the pkill command for managing browser processes.
  • Evidence: The 'Resource Cleanup' section includes code snippets like subprocess.run(['pkill', '-f', 'chrome'], capture_output=True) to terminate residual browser instances.
  • [INDIRECT_PROMPT_INJECTION]: The skill is fundamentally designed to ingest and process data from arbitrary, untrusted external sources (websites and APIs), creating a surface for indirect prompt injection attacks.
  • Ingestion points: The skill instructions (SKILL.md) detail the use of libraries like requests, BeautifulSoup4, Selenium, and Playwright to fetch content from any user-provided URL.
  • Boundary markers: The provided code examples and instructions do not include specific boundary markers or 'ignore' instructions for the data being parsed.
  • Capability inventory: The skill utilizes subprocess.run (for process management), as well as file Write and Edit tools for data storage and script development.
  • Sanitization: There are no explicit mentions of sanitizing or escaping the scraped content before it is processed by the agent or stored.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 05:41 PM
Security Audit — agent-trust-hub — web-scraping-automation