cookiecloud-sync

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs a network request to a user-defined server (COOKIE_CLOUD_HOST) to download encrypted session data.
  • [CREDENTIALS_UNSAFE]: The skill requires and processes sensitive credentials, specifically a UUID and an encryption password. It instructs the agent to read these from environment variables or ask the user, providing mitigation advice against hardcoding secrets in source code.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection as it ingests and processes data from an external, potentially attacker-controlled host.
  • Ingestion points: Reads encrypted JSON data from the URL {HOST}/get/{UUID}.
  • Boundary markers: None specified for the external data payload.
  • Capability inventory: The skill writes code to inject cookies into browser contexts (Playwright, Puppeteer, Selenium) and performs HTTP requests.
  • Sanitization: Relies on JSON.parse and local decryption, but does not explicitly describe sanitization of the decrypted session data before it is processed by the agent or injected into the project.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:36 AM