cloudflare-bypass
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill's primary function is to guide the agent in scraping external, untrusted web content, which constitutes an indirect prompt injection attack surface.
- Ingestion points: Data extracted from external websites during scraping (SKILL.md)
- Boundary markers: No delimiters or specific instructions to ignore embedded commands are provided in the code snippets
- Capability inventory: Uses the browser tool and curl for network operations and script execution
- Sanitization: No sanitization, filtering, or validation steps for the scraped content are described in the bypass workflow
Audit Metadata