web-search-scraper-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and parse content from arbitrary external URLs provided by the user or found during research. This introduces an attack surface where a malicious website could embed instructions designed to manipulate the agent's behavior after the content is processed.
  • Ingestion points: External URLs processed by scripts/web_search_scraper_api.py via the BrowserAct API.
  • Boundary markers: None identified in the prompt templates or the script output handling.
  • Capability inventory: The skill has file-write and network operation capabilities inherent to its purpose (making API calls and potentially saving the resulting markdown).
  • Sanitization: No explicit sanitization of the scraped markdown content is performed before it is returned to the agent.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to api.browseract.com to trigger scraping tasks and retrieve results. These requests are directed to the vendor's official API infrastructure and are consistent with the skill's primary purpose.
  • [COMMAND_EXECUTION]: The skill uses a Python script (scripts/web_search_scraper_api.py) to interact with the API. The SKILL.md file correctly identifies python as a requirement and instructs the agent to execute the script via the command line.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — web-search-scraper-api-skill