local-discovery
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on extracting information from external web sources which could contain malicious instructions.
- Ingestion points: Untrusted data is ingested from various event and venue websites via
web_extractandbrowser_navigateas described in SKILL.md. - Boundary markers: No specific boundary markers or 'ignore' instructions are provided to the agent for processing the external content.
- Capability inventory: The skill instructions in SKILL.md only involve web-based tools (
web_search,web_extract,browser_navigate) and do not utilize any sensitive capabilities like file writing or shell access. - Sanitization: There is no evidence of sanitization or input validation for the data retrieved from external sources.
Audit Metadata