webmcp-gen

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external web pages to generate tool descriptions and logic.
  • Ingestion points: External page content explored via agent-browser (SKILL.md).
  • Boundary markers: The instructions advise treating page content as untrusted, but there are no formal delimiters defined for the data interpolation.
  • Capability inventory: The skill uses agent-browser to execute shell commands and interact with web pages.
  • Sanitization: Instructions recommend excluding secrets, but there is no specific logic to sanitize or escape instructions embedded in the web content before processing.
  • [DYNAMIC_EXECUTION]: The skill generates a JavaScript file (webmcp.init.js) at runtime and subsequently executes it using the agent-browser --init-script command, which constitutes dynamic script assembly and execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:41 PM