stealth-scraper

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides Python and JavaScript templates for browser automation and HTTP requests.
  • [EXTERNAL_DOWNLOADS]: Recommends the installation and use of the curl_cffi Python package and references third-party proxy and CAPTCHA solving services.
  • [PROMPT_INJECTION]: The skill facilitates web scraping, creating a surface for indirect prompt injection.
  • Ingestion points: External data enters the agent context through curl_cffi requests and browser-based content extraction as described in SKILL.md.
  • Boundary markers: Absent; there are no instructions or delimiters provided to ensure the agent ignores or sanitizes instructions embedded in the scraped content.
  • Capability inventory: The skill leverages network operations and browser automation to interact with external websites.
  • Sanitization: No content validation or sanitization logic is present for the data retrieved from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 04:09 PM
Security Audit — agent-trust-hub — stealth-scraper