vr-avatar-engineer
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest untrusted data from external websites and technical papers using
mcp__firecrawl__firecrawl_searchandWebFetch.\n - Ingestion points:
mcp__firecrawl__firecrawl_searchandWebFetchtools (referenced in SKILL.md frontmatter and MCP Integrations table).\n - Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to ignore instructions within the fetched content.\n
- Capability inventory: The agent has access to
Bash,Write,Edit, andmcp__stability-ai__stability-ai-generate-image.\n - Sanitization: Absent. There are no instructions for validating or escaping the external content before processing it with the available tools.
Audit Metadata