isitagentready
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/create_report_packet.pyexecutesgit rev-parse --show-toplevelto programmatically determine the repository root. This is a standard and benign use of subprocess calls for repository management. - [COMMAND_EXECUTION]: The
scripts/test_skill.pyscript usessubprocess.runto invoke the skill's internal scripts (create_report_packet.pyandscan_site.py) as part of its validation and testing suite. - [EXTERNAL_DOWNLOADS]: The
scripts/scan_site.pyscript makes a network request tohttps://isitagentready.com/api/scanto retrieve audit results. This targets the well-known service associated with the skill's primary function to retrieve scan data for a user-provided URL. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes untrusted data.
- Ingestion points: The skill reads local repository files (e.g.,
robots.txt,sitemap.xml) and fetches JSON data from theisitagentready.comAPI inscripts/scan_site.py. - Boundary markers: The instructions in
SKILL.mdandreferences/report-format.mddefine a structured reporting format using templates, which acts as a logical boundary, though no explicit security delimiters are used for the content of the files themselves. - Capability inventory: The skill has the capability to write files (creating the report packet), perform network operations (
scripts/scan_site.py), and execute shell commands viagitand local python scripts (scripts/create_report_packet.py,scripts/test_skill.py). - Sanitization: The skill performs minimal sanitization; it uses template replacement to insert variables into the report but does not explicitly filter or escape the content gathered from repository files or API responses.
Audit Metadata