webcmd-usage
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill describes installing the core utility from the author's npm package and GitHub repository. It also details a plugin system that allows for installing extensions from arbitrary GitHub repositories.\n- [COMMAND_EXECUTION]: The utility allows for the registration and installation of external CLI tools through arbitrary shell commands, such as 'npm i -g'.\n- [DATA_EXFILTRATION]: The utility interacts with authenticated websites using browser sessions and cookies through its 'COOKIE' and 'INTERCEPT' strategies to perform automated tasks.\n- [PROMPT_INJECTION]: The skill describes a high-capability tool that ingests untrusted data from external websites, creating an indirect prompt injection surface.\n
- Ingestion points: External website content accessed via various adapter strategies (PUBLIC, COOKIE, UI) and browser automation tools.\n
- Boundary markers: None identified in the orientation documentation to distinguish between instructions and data.\n
- Capability inventory: Includes plugin execution, external CLI passthrough, and automated browser interactions capable of state changes.\n
- Sanitization: No sanitization or validation mechanisms are described for processing external site data before it affects agent behavior.
Audit Metadata