web-shader-extractor
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The SKILL.md file contains a command to install Node.js by extracting a tarball directly into /usr/local. This is a system-wide directory that typically requires root privileges, and the skill attempts this installation automatically without user intervention.
- [EXTERNAL_DOWNLOADS]: The skill's environment setup in Phase 0 automatically downloads and installs the playwright package and the chromium browser using npm and npx. It also fetches the Node.js runtime from nodejs.org, a well-known external service.
- [COMMAND_EXECUTION]: The scripts/fetch-rendered-dom.mjs script utilizes child_process.execSync to run shell commands for managing Node.js packages and browser binaries at runtime.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from arbitrary URLs provided by the user, creating a vulnerability surface.
- Ingestion points: scripts/fetch-rendered-dom.mjs uses Playwright to visit and render external websites, while SKILL.md uses curl to fetch raw HTML and JS bundles.
- Boundary markers: No delimiters or specific instructions are provided to prevent the agent from being influenced by malicious instructions that might be embedded in the extracted web content.
- Capability inventory: The skill has the ability to execute shell commands, write files to the local system, and perform network requests.
- Sanitization: The skill does not implement sanitization or validation of the code extracted from external sites before it is analyzed by the agent.
- [DYNAMIC_EXECUTION]: The skill reverse-engineers minified JavaScript and shader code from external websites and reconstructs it into new, executable JS and GLSL files, which involves generating code from untrusted sources.
Audit Metadata