stealth-scraper
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides Python and JavaScript templates for browser automation and HTTP requests.
- [EXTERNAL_DOWNLOADS]: Recommends the installation and use of the
curl_cffiPython package and references third-party proxy and CAPTCHA solving services. - [PROMPT_INJECTION]: The skill facilitates web scraping, creating a surface for indirect prompt injection.
- Ingestion points: External data enters the agent context through
curl_cffirequests and browser-based content extraction as described inSKILL.md. - Boundary markers: Absent; there are no instructions or delimiters provided to ensure the agent ignores or sanitizes instructions embedded in the scraped content.
- Capability inventory: The skill leverages network operations and browser automation to interact with external websites.
- Sanitization: No content validation or sanitization logic is present for the data retrieved from external sources.
Audit Metadata