extract-tool-registration
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
ego-browserto execute Node.js scripts that automate web interactions, including form filling, button clicking, and navigating complex UI flows. It also includes a bash script that usescurlfor API communication. - [EXTERNAL_DOWNLOADS]: Communicates with external domains
bibigpt.coandapi.bibigpt.coto perform registrations and validate API tokens. - [DYNAMIC_EXECUTION]: Employs Node.js code blocks within browser automation tasks and uses
python3 -cfor inline JSON processing in the provided bash script. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from the
bibigpt.cowebsite. Ingestion points: Data is read from the browser DOM inSKILL.md(e.g.,input[readonly]). Boundary markers: None explicitly defined for the extracted token data. Capability inventory: Subprocess calls viaego-browser, network operations viacurl, and suggested local file writing. Sanitization: No specific sanitization or validation of the extracted token string before usage.
Audit Metadata