brand-style
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [Indirect Prompt Injection] The skill utilizes the WebFetch tool to extract information such as taglines and metadata from external URLs provided by the user. This creates a vulnerability surface where a malicious website could host hidden instructions designed to influence the agent's future behavior or poison the 'Business context' block where this data is persisted.
- [External Downloads] The skill performs network operations to fetch and analyze external websites. While this is the primary purpose of the skill, interacting with unknown and untrusted hosts carries inherent risks of data exposure or processing malicious content.
Audit Metadata