data-scraper-agent
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill architecture contains an attack surface for indirect prompt injection because it is designed to ingest and process untrusted data from external websites.
- Ingestion points: Data is fetched from arbitrary external URLs and APIs in the
scraper/sources/modules using therequestslibrary andBeautifulSoup. - Boundary markers: While the prompt template in
ai/pipeline.pyusesjson.dumps()to structure the data, it lacks explicit negative constraints or instructions for the AI model to ignore commands or formatting embedded within the scraped content. - Capability inventory: The agent is equipped with network access for scraping and API-based write access to storage providers like Notion. It does not possess capabilities for arbitrary command execution or sensitive local file system modification.
- Sanitization: The fetched content is passed to the AI enrichment layer without sanitization or filtering of potential prompt injection patterns.
Audit Metadata