skills/hk-hub/agentskills/defuddle/Gen Agent Trust Hub

defuddle

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates for executing shell commands, such as defuddle parse <url> --md. If the agent interpolates user-provided URLs directly into these commands without rigorous sanitization, it could lead to command injection attacks.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install an external package from a public registry using npm install -g defuddle. This introduces a dependency on third-party code that is not hosted within the skill's repository or provided by a recognized trusted vendor.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and process data from external web pages, which is a significant attack surface for indirect prompt injection.
  • Ingestion points: External web content retrieved from user-provided URLs (SKILL.md).
  • Boundary markers: None. The instructions do not recommend using delimiters or providing specific guidance to the agent to ignore instructions found within the fetched content.
  • Capability inventory: The skill has the ability to execute shell commands and write output to files (-o content.md).
  • Sanitization: None. There are no instructions for filtering or escaping the fetched content before the agent processes it.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — defuddle