webcmd-browser-sitemap

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill instructions or metadata.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash(webcmd:*) tool. This is a restricted toolset intended for interacting with the webcmd browser utility and is appropriate for the skill's navigation purpose.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads and writes to ~/.webcmd/sites/ and sitemaps/. This file access is limited to application-specific data and does not involve accessing sensitive system files or credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from sitemap files. While this presents a potential attack surface, the skill instructions mitigate this by directing the agent to prioritize live browser reality over static file content.
  • Ingestion points: ~/.webcmd/sites/<site>/sitemap/ and sitemaps/<site>/ referenced in SKILL.md.
  • Boundary markers: Absent, however, the instructions include a 'Trust Reality' rule that explicitly warns against trusting sitemap content over live state.
  • Capability inventory: Bash(webcmd:*), Read, Edit, Write, Grep as defined in the allowed-tools of SKILL.md.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 08:02 AM
Security Audit — agent-trust-hub — webcmd-browser-sitemap