webscrapingai

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the membrane command-line interface to perform actions, manage connections, and proxy requests to the WebScraping.AI API. This is the primary mechanism for the skill's functionality.\n- [EXTERNAL_DOWNLOADS]: The instructions direct the user to install and run the @membranehq/cli package from NPM. This is a legitimate tool provided by the vendor for interacting with their platform.\n- [PROMPT_INJECTION]: The skill processes data from external websites via WebScraping.AI. This presents an indirect prompt injection surface where instructions in scraped content could potentially be seen by the agent, though no active exploitation is present in the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 09:41 AM
Security Audit — agent-trust-hub — webscrapingai