data-fair-browse
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses npx to run @data-fair/nhi-proxy, a tool from the skill's authoring organization.
- [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands such as npx to start services and curl to verify identity and interact with APIs through a local proxy.
- [DYNAMIC_EXECUTION]: The skill utilizes browser automation to execute JavaScript within the context of platform web pages to interact with page-level tools.
- [INDIRECT_PROMPT_INJECTION]: The skill documents the use of subagent tools that return prompts and instructions from the platform for the agent to follow.
- Ingestion points: Data returned by navigator.modelContext.callTool for subagent_* tools and platform guidance tools as specified in references/webmcp.md.
- Boundary markers: No explicit delimiters or safety warnings are provided for the instructions returned by these tools.
- Capability inventory: The agent has capabilities for shell command execution, browser script execution, and network access.
- Sanitization: The documentation does not specify sanitization or validation for instructions received from platform tools before agent execution.
- [DATA_EXFILTRATION]: The skill references a sensitive local configuration directory ~/.config/nhi-proxy/ for accessing CA certificates and warns the agent against reading signing keys, acknowledging the presence of sensitive local data.
Audit Metadata