webmcp-gen
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external web pages to generate tool descriptions and logic.
- Ingestion points: External page content explored via
agent-browser(SKILL.md). - Boundary markers: The instructions advise treating page content as untrusted, but there are no formal delimiters defined for the data interpolation.
- Capability inventory: The skill uses
agent-browserto execute shell commands and interact with web pages. - Sanitization: Instructions recommend excluding secrets, but there is no specific logic to sanitize or escape instructions embedded in the web content before processing.
- [DYNAMIC_EXECUTION]: The skill generates a JavaScript file (
webmcp.init.js) at runtime and subsequently executes it using theagent-browser --init-scriptcommand, which constitutes dynamic script assembly and execution.
Audit Metadata