web-search-scraper-api-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and parse content from arbitrary external URLs provided by the user or found during research. This introduces an attack surface where a malicious website could embed instructions designed to manipulate the agent's behavior after the content is processed.
- Ingestion points: External URLs processed by
scripts/web_search_scraper_api.pyvia the BrowserAct API. - Boundary markers: None identified in the prompt templates or the script output handling.
- Capability inventory: The skill has file-write and network operation capabilities inherent to its purpose (making API calls and potentially saving the resulting markdown).
- Sanitization: No explicit sanitization of the scraped markdown content is performed before it is returned to the agent.
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to
api.browseract.comto trigger scraping tasks and retrieve results. These requests are directed to the vendor's official API infrastructure and are consistent with the skill's primary purpose. - [COMMAND_EXECUTION]: The skill uses a Python script (
scripts/web_search_scraper_api.py) to interact with the API. TheSKILL.mdfile correctly identifiespythonas a requirement and instructs the agent to execute the script via the command line.
Audit Metadata