skills/cyranob/web-forager/fact-check/Gen Agent Trust Hub

fact-check

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses uvx to install and run the web-forager package and uv run to install the ddgs (DuckDuckGo Search) library for search operations. These dependencies are directly related to the skill's primary function of evidence gathering.
  • [COMMAND_EXECUTION]: The skill executes shell commands to perform web searches and fetch page content using curl.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from the open web, creating a surface for indirect prompt injection. Ingestion points: Article content fetched through r.jina.ai and search snippets from ddgs. Boundary markers: Not specified in the instructions. Capability inventory: The skill has network access and the ability to execute shell commands via uv. Sanitization: No specific sanitization or filtering is defined for the external web content before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 09:23 AM
Security Audit — agent-trust-hub — fact-check