webmcp-agents

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The repository includes a Makefile and scripts/validate-skills.sh used for specification builds, linting, and repository hygiene. These tools are standard for specification development and maintenance.
  • [EXTERNAL_DOWNLOADS]: The Makefile fetches rendered specification content from the official CSSWG Bikeshed API (https://api.csswg.org/bikeshed/). This is a well-known service used by W3C and WHATWG for compiling specification source documents.
  • [INDIRECT_PROMPT_INJECTION]: The webmcp-agent-browser skill defines an operational surface where the agent ingests untrusted content from live web pages. The suite mitigates this risk by providing extensive normative and operational guidance on defense-in-depth, including the use of output classifiers, spotlighting delimiters, and mandatory human-in-the-loop confirmation for high-impact actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 11:23 AM
Security Audit — agent-trust-hub — webmcp-agents