cookiecloud-sync
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs a network request to a user-defined server (COOKIE_CLOUD_HOST) to download encrypted session data.
- [CREDENTIALS_UNSAFE]: The skill requires and processes sensitive credentials, specifically a UUID and an encryption password. It instructs the agent to read these from environment variables or ask the user, providing mitigation advice against hardcoding secrets in source code.
- [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection as it ingests and processes data from an external, potentially attacker-controlled host.
- Ingestion points: Reads encrypted JSON data from the URL
{HOST}/get/{UUID}. - Boundary markers: None specified for the external data payload.
- Capability inventory: The skill writes code to inject cookies into browser contexts (Playwright, Puppeteer, Selenium) and performs HTTP requests.
- Sanitization: Relies on
JSON.parseand local decryption, but does not explicitly describe sanitization of the decrypted session data before it is processed by the agent or injected into the project.
Audit Metadata