hybrid-scrape-stack

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest data from external web sources, creating an inherent surface for indirect prompt injection where malicious instructions could be embedded in scraped HTML or JSON content.
  • Ingestion points: External web content retrieved through httpx, Playwright, and various managed extraction platforms.
  • Boundary markers: The skill references agent-skills/runtime-compliance-evaluator/SKILL.md and explicitly instructs checking legal_mode and risk_mode before extraction.
  • Capability inventory: Extensive network communication capabilities and browser automation; ability to save extractor plans and fixtures to local storage.
  • Sanitization: The skill provides architectural guidance but does not specify runtime sanitization methods for the extracted data.
  • [DATA_EXFILTRATION]: The skill facilitates network connections to arbitrary external domains and third-party managed scraping services (Zyte, Browserbase, Firecrawl). While these are intended for legitimate data extraction, the network access capabilities are extensive.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes several well-known and trusted third-party libraries and services for scraping and browser orchestration, which is standard practice for this use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 02:17 AM
Security Audit — agent-trust-hub — hybrid-scrape-stack