construction-sweep

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface.\n
  • The skill scrapes business information from external websites and Facebook pages and stores it in CSV and JSON formats.\n
  • Ingestion points: Untrusted content is fetched via scripts/pull_firecrawl.py and Apify MCP tools from URLs found on the web.\n
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard instructions within the scraped text when reading the processed files.\n
  • Capability inventory: The skill possesses the capability to write to the local file system (CSV/JSON output) and perform network operations (API calls).\n
  • Sanitization: The scripts extract specific data points like emails and license numbers but do not perform sanitization to strip potential prompt-based attacks from the descriptive text fields or business bios.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 11:52 AM
Security Audit — agent-trust-hub — construction-sweep