fetcher
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
run.shscript includes a suggestion to install theuvtool by piping a script fromastral.shdirectly to the shell. - [EXTERNAL_DOWNLOADS]: The skill is designed to download and execute its core components at runtime from the author's repository at
github.com/grahama1970/fetcher.gitusing theuvxtool. - [COMMAND_EXECUTION]: The
scripts/fetch_sparta.pyscript utilizessubprocess.Popento execute the localrun.shscript, passing URL data through standard input. - [PROMPT_INJECTION]: As a web fetching tool, the skill ingests content from untrusted external websites, creating a surface for indirect prompt injection.
- Ingestion points: The skill retrieves data from arbitrary URLs via the
run.shentry point. - Boundary markers: No explicit delimiters are implemented in the local scripts to isolate the retrieved web content from the agent's instructions.
- Capability inventory: The skill can perform network operations, write to the filesystem, and execute shell commands.
- Sanitization: The skill extracts text from raw HTML, but the provided scripts do not include additional sanitization or filtering of the extracted content before it is passed to the agent.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata