skyvern
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates browsing and extracting data from arbitrary third-party websites, which introduces a risk of indirect prompt injection where malicious instructions on a webpage could influence the agent's behavior.
- Ingestion points: External web content retrieved during automation tasks in SKILL.md.
- Boundary markers: Absent; the instructions do not include specific delimiters or warnings to ignore instructions within retrieved data.
- Capability inventory: Substantial, including clicking, typing, form submission, file downloads, and 75+ MCP tools for network and session management.
- Sanitization: Not specified in the skill configuration.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 'skyvern' package from PyPI. This is the standard distribution method for this automation framework.
- [DATA_EXFILTRATION]: The tool is designed to handle sensitive data, including stored credentials and file downloads (e.g., invoices). Users should ensure they trust the configured MCP server ('api.skyvern.com') and the Skyvern platform with this information.
Audit Metadata