webmcp-agents
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The repository includes a
Makefileandscripts/validate-skills.shused for specification builds, linting, and repository hygiene. These tools are standard for specification development and maintenance. - [EXTERNAL_DOWNLOADS]: The
Makefilefetches rendered specification content from the official CSSWG Bikeshed API (https://api.csswg.org/bikeshed/). This is a well-known service used by W3C and WHATWG for compiling specification source documents. - [INDIRECT_PROMPT_INJECTION]: The
webmcp-agent-browserskill defines an operational surface where the agent ingests untrusted content from live web pages. The suite mitigates this risk by providing extensive normative and operational guidance on defense-in-depth, including the use of output classifiers, spotlighting delimiters, and mandatory human-in-the-loop confirmation for high-impact actions.
Audit Metadata