fetch-url-as-markdown

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches content from arbitrary external URLs provided by the user. This data ingestion surface is vulnerable to indirect prompt injection, where a malicious website could include hidden or overt instructions designed to override the agent's behavior when the content is processed.
  • Ingestion points: The scripts/fetch_url.py script takes a URL argument, fetches the response body, and outputs extracted text to stdout.
  • Boundary markers: The output is provided as raw Markdown. The skill instructions in SKILL.md do not mandate the use of boundary markers or "ignore instructions" wrappers when the agent processes the fetched content.
  • Capability inventory: The script performs network operations to retrieve URL content and processes it locally using the trafilatura library.
  • Sanitization: While the trafilatura library extracts main content and removes boilerplate, it does not sanitize the resulting text for adversarial instructions intended for the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:08 AM
Security Audit — agent-trust-hub — fetch-url-as-markdown