skills/exboys/skilllite/web-search/Gen Agent Trust Hub

web-search

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the infsh CLI and related skills from the inference.sh platform. These resources are provided by the platform vendor and are necessary for the skill's stated functionality.
  • [PROMPT_INJECTION]: As a tool for web search and extraction, this skill introduces a surface for indirect prompt injection by bringing external web content into the agent's context.
  • Ingestion points: Data returned by search and extraction commands (e.g., infsh app run tavily/search-assistant).
  • Boundary markers: The skill does not define specific markers or instructions to isolate untrusted web data.
  • Capability inventory: Execution of the infsh CLI via Bash.
  • Sanitization: No sanitization or validation of the retrieved web content is implemented within the skill instructions.
  • [COMMAND_EXECUTION]: The skill follows security best practices by using the allowed-tools frontmatter to restrict the agent's shell access specifically to the infsh CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 01:20 PM
Security Audit — agent-trust-hub — web-search