webgpt-review
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell scripts (
scripts/run-webgpt-review.sh) which in turn invoke other tool-providing scripts (ask/run.shandsurf/run.sh) located in sibling directories. These executions use bash arrays to safely handle arguments and prevent shell injection. - [EXTERNAL_DEPENDENCIES]: The skill relies on the presence of specific sibling skills (
ask,surf, andbest-practices-skills) within the environment's directory structure for core functionality and automated testing. - [INDIRECT_PROMPT_INJECTION]: The skill implements an attack surface for indirect prompt injection by design, as its primary purpose is to ingest external data (via the
--bundlefile) and user-provided--instructionsfor processing by a downstream agent (WebGPT). - Ingestion points: External bundle files (concatenated text or zip) and user-supplied instruction strings.
- Boundary markers: The skill contract specifies that bundles must be browser-readable artifacts, but does not implement explicit delimiters to separate data from instructions within the bundle.
- Capability inventory: The skill has the ability to execute subprocesses and interface with browser automation tools.
- Sanitization: The script performs basic validation on the bundle's file type and existence but does not sanitize the contents of the file before submission.
Audit Metadata