map
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill involves ingesting external reading materials (books, articles, documents) fetched via tools like WebFetch. This represents an entry point for untrusted data that could potentially contain hidden instructions. However, because the skill's capabilities are limited to concept extraction, classification, and generating Mermaid diagrams, the risk of successful exploitation is minimal. No specific boundary markers or sanitization procedures are defined for the ingested text.
- [COMMAND_EXECUTION]: The instructions reference tools like 'defuddle/WebFetch' for text extraction. These appear to be standard utility tools for the agent platform rather than arbitrary shell command execution or risky system calls.
Audit Metadata