backlinks-referring-domains
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local shell script 'scripts/get_backlinks_referring_domains.sh' which uses python3 for JSON processing and curl for API requests.
- [EXTERNAL_DOWNLOADS]: The skill retrieves data from the external service at 'https://ai-factory.frevana.com'.
- [DATA_EXFILTRATION]: The skill transmits user-provided search parameters and an authentication token to the Frevana API endpoint.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes external data from an API response. Ingestion points: API data returned to 'scripts/get_backlinks_referring_domains.sh'. Boundary markers: None present. Capability inventory: Local file writing and network access. Sanitization: The script performs JSON validation on the response.
Audit Metadata