fetcher

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The run.sh script includes a suggestion to install the uv tool by piping a script from astral.sh directly to the shell.
  • [EXTERNAL_DOWNLOADS]: The skill is designed to download and execute its core components at runtime from the author's repository at github.com/grahama1970/fetcher.git using the uvx tool.
  • [COMMAND_EXECUTION]: The scripts/fetch_sparta.py script utilizes subprocess.Popen to execute the local run.sh script, passing URL data through standard input.
  • [PROMPT_INJECTION]: As a web fetching tool, the skill ingests content from untrusted external websites, creating a surface for indirect prompt injection.
  • Ingestion points: The skill retrieves data from arbitrary URLs via the run.sh entry point.
  • Boundary markers: No explicit delimiters are implemented in the local scripts to isolate the retrieved web content from the agent's instructions.
  • Capability inventory: The skill can perform network operations, write to the filesystem, and execute shell commands.
  • Sanitization: The skill extracts text from raw HTML, but the provided scripts do not include additional sanitization or filtering of the extracted content before it is passed to the agent.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — fetcher