spider
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch content from external URLs and pass the resulting data directly into LLM prompts for analysis and structured data extraction.
- Ingestion points: Untrusted content is ingested via
curlin the "Page Analysis", "Security Scan", and "Extract Structured Data" sections ofSKILL.md. - Boundary markers: The skill uses simple text headers (e.g., "Analyze this webpage:", "HEADERS:", "CONTENT SAMPLE:") but lacks robust delimiters or explicit instructions to the AI to ignore embedded commands within the fetched data.
- Capability inventory: The environment has access to
curl,bash,python3, and thegeminiCLI tool. - Sanitization: No sanitization or filtering is performed on the ingested content before it is interpolated into the prompts.
- [DYNAMIC_EXECUTION]: The skill demonstrates the use of
python3 -cto execute a multi-line Python script provided as a string literal for HTML parsing. - Evidence: The "Extract Text Content" section pipes
curloutput to a static Python script defined within the bash command. - Context: This is a low-risk pattern used for data processing rather than executing untrusted code, as the Python logic is hardcoded in the skill and only the input data is dynamic.
Recommendations
- HIGH: Downloads and executes remote code from: https://example.com - DO NOT USE without thorough review
Audit Metadata