data-scraper-agent

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests data from external websites and processes it through an LLM. Evidence: 1. Ingestion points: Data enters the system via requests and playwright in the scraper/sources/ directory and main orchestrator. 2. Boundary markers: The prompt template in ai/pipeline.py uses Markdown headers for structure but does not include explicit instructions to ignore instructions found within the scraped data. 3. Capability inventory: The skill can perform network requests and write to Notion or other storage backends. 4. Sanitization: No sanitization or escaping is applied to the scraped content before it is included in the AI prompt.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to scrape user-defined websites and to interact with Google's Gemini API (generativelanguage.googleapis.com) for data enrichment. These operations are consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — data-scraper-agent