skills/johnlindquist/claude/spider/Gen Agent Trust Hub

spider

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch content from external URLs and pass the resulting data directly into LLM prompts for analysis and structured data extraction.
  • Ingestion points: Untrusted content is ingested via curl in the "Page Analysis", "Security Scan", and "Extract Structured Data" sections of SKILL.md.
  • Boundary markers: The skill uses simple text headers (e.g., "Analyze this webpage:", "HEADERS:", "CONTENT SAMPLE:") but lacks robust delimiters or explicit instructions to the AI to ignore embedded commands within the fetched data.
  • Capability inventory: The environment has access to curl, bash, python3, and the gemini CLI tool.
  • Sanitization: No sanitization or filtering is performed on the ingested content before it is interpolated into the prompts.
  • [DYNAMIC_EXECUTION]: The skill demonstrates the use of python3 -c to execute a multi-line Python script provided as a string literal for HTML parsing.
  • Evidence: The "Extract Text Content" section pipes curl output to a static Python script defined within the bash command.
  • Context: This is a low-risk pattern used for data processing rather than executing untrusted code, as the Python logic is hardcoded in the skill and only the input data is dynamic.
Recommendations
  • HIGH: Downloads and executes remote code from: https://example.com - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — spider