web-scraping-automation
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides implementation patterns that use
subprocess.runto execute thepkillcommand for managing browser processes. - Evidence: The 'Resource Cleanup' section includes code snippets like
subprocess.run(['pkill', '-f', 'chrome'], capture_output=True)to terminate residual browser instances. - [INDIRECT_PROMPT_INJECTION]: The skill is fundamentally designed to ingest and process data from arbitrary, untrusted external sources (websites and APIs), creating a surface for indirect prompt injection attacks.
- Ingestion points: The skill instructions (SKILL.md) detail the use of libraries like
requests,BeautifulSoup4,Selenium, andPlaywrightto fetch content from any user-provided URL. - Boundary markers: The provided code examples and instructions do not include specific boundary markers or 'ignore' instructions for the data being parsed.
- Capability inventory: The skill utilizes
subprocess.run(for process management), as well as fileWriteandEdittools for data storage and script development. - Sanitization: There are no explicit mentions of sanitizing or escaping the scraped content before it is processed by the agent or stored.
Audit Metadata