zillow-scraper

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides instructions for scraping external data from Zillow. This creates an indirect prompt injection surface where the agent might process untrusted data (such as property descriptions or listing metadata) as instructions.
  • Ingestion points: Scraped data from Zillow search result pages and property detail pages.
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands in the scraped content.
  • Capability inventory: Browser tool usage for navigation and data extraction.
  • Sanitization: Absent; the skill does not specify any validation or filtering of the scraped content.
  • [NO_CODE]: The skill consists entirely of instructional markdown and configuration templates in the SKILL.md file. It does not include any executable scripts, binary files, or dependency manifests.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 08:23 AM
Security Audit — agent-trust-hub — zillow-scraper