business-contact-social-links-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to execute a Python script (
business_contact_social_links.py) to process company names and website URLs.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes the 'requests' Python library to communicate with an external API atapi.browseract.com. While these are vendor-provided resources, they involve external network communication.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from third-party websites, which could contain malicious instructions designed to influence the agent.\n - Ingestion points: Content is retrieved from external websites and search results via the
api.browseract.comworkflow inscripts/business_contact_social_links.py.\n - Boundary markers: The script outputs data as strings or JSON to the terminal without specific delimiters or warnings to the agent to ignore instructions embedded within the scraped data.\n
- Capability inventory: The agent has the capability to execute scripts and access the network as part of this skill's functionality.\n
- Sanitization: There is no evidence of content sanitization, filtering, or validation of the data returned from the external scraping service before it is passed to the agent context.
Audit Metadata