structured-extraction

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external websites via the scrape tool. \n
  • Ingestion points: Website content extracted using the scrape tool. \n
  • Boundary markers: The skill does not define specific prompt delimiters for external content but instructs the agent to validate the output against a strict JSON schema. \n
  • Capability inventory: The skill uses bashExec for jq processing and spawnAgents for parallel scraping. \n
  • Sanitization: Requires validation of required fields, data types, and citation URLs before final output. \n- [COMMAND_EXECUTION]: The skill suggests using bashExec with jq to merge JSON files in the /data/ directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 06:29 AM
Security Audit — agent-trust-hub — structured-extraction