webgpt-review

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell scripts (scripts/run-webgpt-review.sh) which in turn invoke other tool-providing scripts (ask/run.sh and surf/run.sh) located in sibling directories. These executions use bash arrays to safely handle arguments and prevent shell injection.
  • [EXTERNAL_DEPENDENCIES]: The skill relies on the presence of specific sibling skills (ask, surf, and best-practices-skills) within the environment's directory structure for core functionality and automated testing.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an attack surface for indirect prompt injection by design, as its primary purpose is to ingest external data (via the --bundle file) and user-provided --instructions for processing by a downstream agent (WebGPT).
  • Ingestion points: External bundle files (concatenated text or zip) and user-supplied instruction strings.
  • Boundary markers: The skill contract specifies that bundles must be browser-readable artifacts, but does not implement explicit delimiters to separate data from instructions within the bundle.
  • Capability inventory: The skill has the ability to execute subprocesses and interface with browser automation tools.
  • Sanitization: The script performs basic validation on the bundle's file type and existence but does not sanitize the contents of the file before submission.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — webgpt-review