opencli-sitemap-author
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bash(opencli:*)tool to execute commands likeopencli browser state,find,network, andanalyzefor site exploration and data verification.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external websites viaopencli browseras part of its sitemap authoring workflow.\n - Ingestion points: Website content and browser metadata retrieved using
opencli browser(SKILL.md).\n - Boundary markers: The skill includes 'Red Lines' and validation schema rules (references/sitemap-schema.md) to prevent the inclusion of unsafe data, though it does not specify explicit delimiters for all external content.\n
- Capability inventory: The skill has access to
Bash,Read,Edit,Write, andGreptools.\n - Sanitization: Instructions require capturing only semantic structures and explicitly forbid recording secrets, authentication strategies, or security bypass techniques.
Audit Metadata