data-scraper-agent
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It scrapes content from external, untrusted websites and interpolates this data directly into prompts sent to the Gemini AI model.
- Ingestion points: Data is fetched from external URLs via
requestsorplaywrightin thescraper/sources/directory (e.g.,scraper/sources/my_source.py). - Boundary markers: While the prompt template in
ai/pipeline.pyuses markdown headers (e.g.,# Items), it lacks strong delimiters or explicit instructions to the model to disregard potentially malicious commands embedded within the scraped content. - Capability inventory: The resulting agent has network access (to Gemini and storage providers) and the ability to commit changes to its own GitHub repository via automated workflows.
- Sanitization: The skill does not implement filtering or sanitization of the scraped text before it is presented to the LLM, creating a surface where attacker-controlled website content could influence the agent's scoring or summarization logic.
Audit Metadata