oauth-helper
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructions contain explicit selectors for identifying and interacting with sensitive credential fields, such as password inputs (
input[type="password"],input#p) and two-factor authentication fields (input#app_totp), across several major login providers. - [INDIRECT_PROMPT_INJECTION]: The agent is instructed to scan external login pages for specific UI elements and display their text to the user. A malicious website could attempt to include instructions within these elements to influence the agent's behavior during the automated flow.
- Ingestion points: External login pages scanned during the detection phase (SKILL.md).
- Boundary markers: None; the agent directly reads and processes text from target web pages without delimiters or isolation.
- Capability inventory: The agent has the ability to navigate URLs, fill out forms, click buttons, and capture screenshots.
- Sanitization: No sanitization is performed on the data extracted from the web pages; the system relies entirely on the Telegram confirmation step for safety.
- [DATA_EXFILTRATION]: The core workflow involves transmitting session-specific data, such as target site names and screenshots of QR codes, to a remote Telegram channel. While configured by the user, this represents a persistent channel for data transmission outside the immediate environment.
Audit Metadata