skills/automattic/studio/adapt/Gen Agent Trust Hub

adapt

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data (HTML, API responses) from user-provided URLs during the reconnaissance and extraction phases, making it susceptible to indirect prompt injection. Ingestion points: Content from remote websites during reconnaissance and extraction. Boundary markers: The instructions do not specify the use of delimiters or 'ignore' warnings when processing external site content. Capability inventory: The skill has access to Bash, Write, and Edit, allowing it to modify the codebase and execute local commands. Sanitization: No sanitization or validation of the ingested external content is described.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform system-level tasks such as checking DNS records during reconnaissance and running the local CLI for testing.
  • [DATA_EXFILTRATION]: The skill instructs the agent to capture sensitive information, including cookies and authorization headers, from the user's browser session via the Chrome DevTools Protocol (CDP) for the purpose of API mapping.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 03:02 AM
Security Audit — agent-trust-hub — adapt