searxng
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
web_url_readtool is designed to fetch and extract content from arbitrary external URLs. This represents a vulnerability surface for indirect prompt injection, where an attacker could place malicious instructions within web content (e.g., hidden in HTML comments, CSS, or metadata) to attempt to override the AI agent's instructions or exfiltrate session data when the content is processed.
Audit Metadata