construction-sweep
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface.\n
- The skill scrapes business information from external websites and Facebook pages and stores it in CSV and JSON formats.\n
- Ingestion points: Untrusted content is fetched via
scripts/pull_firecrawl.pyand Apify MCP tools from URLs found on the web.\n - Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard instructions within the scraped text when reading the processed files.\n
- Capability inventory: The skill possesses the capability to write to the local file system (CSV/JSON output) and perform network operations (API calls).\n
- Sanitization: The scripts extract specific data points like emails and license numbers but do not perform sanitization to strip potential prompt-based attacks from the descriptive text fields or business bios.
Audit Metadata