monitor-website

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs health checks and content validation by fetching data from the vendor's domain (grahama.co). It also communicates with a local memory daemon at http://127.0.0.1:8601 to store and version authored content revisions in an ArangoDB instance.
  • [COMMAND_EXECUTION]: Multiple scripts utilize the subprocess module to perform repository operations, including tracking changes with git, building the static site with npm, and running internal generation scripts like gen_inventory.py and gen_resume.py.
  • [REMOTE_CODE_EXECUTION]: The skill uses uv run to dynamically execute Python scripts for resume export (PDF and DOCX) using pinned versions of legitimate packages such as markdown-pdf and python-docx.
  • [COMMAND_EXECUTION]: The review_site.py script implements a local HTTP server for serving immutable design review bundles. The server uses a randomly generated 24-character nonce to gate access to the review units and associated artifacts.
  • [DATA_EXPOSURE]: The skill ingests data from local README.md and RESUME.md files to update site/content.json and other generated site surfaces. It implements a 'pull' mechanism to retrieve authored project descriptions from the local memory daemon back into the repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted data from the repository's Markdown files and potentially from user-supplied URLs in the design review tool.
  • Ingestion points: README.md, RESUME.md, and arbitrary URLs processed by scripts/design_review.py.
  • Boundary markers: None explicitly implemented to prevent the agent from following instructions embedded in the processed Markdown or HTML content.
  • Capability inventory: File system writes, network requests via urlopen, and shell command execution via subprocess (git, npm, python).
  • Sanitization: The skill employs slugify for project names and validates that artifacts remain within the repository structure to prevent path traversal.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — monitor-website