isitagentready

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/create_report_packet.py executes git rev-parse --show-toplevel to programmatically determine the repository root. This is a standard and benign use of subprocess calls for repository management.
  • [COMMAND_EXECUTION]: The scripts/test_skill.py script uses subprocess.run to invoke the skill's internal scripts (create_report_packet.py and scan_site.py) as part of its validation and testing suite.
  • [EXTERNAL_DOWNLOADS]: The scripts/scan_site.py script makes a network request to https://isitagentready.com/api/scan to retrieve audit results. This targets the well-known service associated with the skill's primary function to retrieve scan data for a user-provided URL.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes untrusted data.
  • Ingestion points: The skill reads local repository files (e.g., robots.txt, sitemap.xml) and fetches JSON data from the isitagentready.com API in scripts/scan_site.py.
  • Boundary markers: The instructions in SKILL.md and references/report-format.md define a structured reporting format using templates, which acts as a logical boundary, though no explicit security delimiters are used for the content of the files themselves.
  • Capability inventory: The skill has the capability to write files (creating the report packet), perform network operations (scripts/scan_site.py), and execute shell commands via git and local python scripts (scripts/create_report_packet.py, scripts/test_skill.py).
  • Sanitization: The skill performs minimal sanitization; it uses template replacement to insert variables into the report but does not explicitly filter or escape the content gathered from repository files or API responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — isitagentready