fetch-url-as-markdown
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches content from arbitrary external URLs provided by the user. This data ingestion surface is vulnerable to indirect prompt injection, where a malicious website could include hidden or overt instructions designed to override the agent's behavior when the content is processed.
- Ingestion points: The
scripts/fetch_url.pyscript takes a URL argument, fetches the response body, and outputs extracted text to stdout. - Boundary markers: The output is provided as raw Markdown. The skill instructions in
SKILL.mddo not mandate the use of boundary markers or "ignore instructions" wrappers when the agent processes the fetched content. - Capability inventory: The script performs network operations to retrieve URL content and processes it locally using the
trafilaturalibrary. - Sanitization: While the
trafilaturalibrary extracts main content and removes boilerplate, it does not sanitize the resulting text for adversarial instructions intended for the LLM.
Audit Metadata