extract-tool-registration

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes ego-browser to execute Node.js scripts that automate web interactions, including form filling, button clicking, and navigating complex UI flows. It also includes a bash script that uses curl for API communication.
  • [EXTERNAL_DOWNLOADS]: Communicates with external domains bibigpt.co and api.bibigpt.co to perform registrations and validate API tokens.
  • [DYNAMIC_EXECUTION]: Employs Node.js code blocks within browser automation tasks and uses python3 -c for inline JSON processing in the provided bash script.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from the bibigpt.co website. Ingestion points: Data is read from the browser DOM in SKILL.md (e.g., input[readonly]). Boundary markers: None explicitly defined for the extracted token data. Capability inventory: Subprocess calls via ego-browser, network operations via curl, and suggested local file writing. Sanitization: No specific sanitization or validation of the extracted token string before usage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:27 AM
Security Audit — agent-trust-hub — extract-tool-registration