ads-dna

Warn

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script using a user-provided URL as a positional argument. There are no instructions to sanitize or validate the URL before execution, which could allow an attacker to inject shell commands via a crafted URL string.- [PROMPT_INJECTION]: The skill ingests untrusted content from external websites to derive brand identity, exposing the agent to indirect prompt injection. * Ingestion points: Visible text, meta tags, and style information retrieved from external URLs via the WebFetch tool. * Boundary markers: Absent. The skill does not specify delimiters or provide instructions to ignore embedded commands within the fetched data. * Capability inventory: Execution of local Python scripts and writing JSON files to the current directory. * Sanitization: Absent. No validation or escaping of the scraped content is performed.- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the Playwright framework and browser binaries from well-known sources if the screenshot functionality is missing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 5, 2026, 06:41 PM
Security Audit — agent-trust-hub — ads-dna