monitor-website
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs health checks and content validation by fetching data from the vendor's domain (grahama.co). It also communicates with a local memory daemon at http://127.0.0.1:8601 to store and version authored content revisions in an ArangoDB instance.
- [COMMAND_EXECUTION]: Multiple scripts utilize the
subprocessmodule to perform repository operations, including tracking changes withgit, building the static site withnpm, and running internal generation scripts likegen_inventory.pyandgen_resume.py. - [REMOTE_CODE_EXECUTION]: The skill uses
uv runto dynamically execute Python scripts for resume export (PDF and DOCX) using pinned versions of legitimate packages such asmarkdown-pdfandpython-docx. - [COMMAND_EXECUTION]: The
review_site.pyscript implements a local HTTP server for serving immutable design review bundles. The server uses a randomly generated 24-character nonce to gate access to the review units and associated artifacts. - [DATA_EXPOSURE]: The skill ingests data from local
README.mdandRESUME.mdfiles to updatesite/content.jsonand other generated site surfaces. It implements a 'pull' mechanism to retrieve authored project descriptions from the local memory daemon back into the repository. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted data from the repository's Markdown files and potentially from user-supplied URLs in the design review tool.
- Ingestion points:
README.md,RESUME.md, and arbitrary URLs processed byscripts/design_review.py. - Boundary markers: None explicitly implemented to prevent the agent from following instructions embedded in the processed Markdown or HTML content.
- Capability inventory: File system writes, network requests via
urlopen, and shell command execution viasubprocess(git, npm, python). - Sanitization: The skill employs
slugifyfor project names and validates that artifacts remain within the repository structure to prevent path traversal.
Audit Metadata