webscrapingai
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
membranecommand-line interface to perform actions, manage connections, and proxy requests to the WebScraping.AI API. This is the primary mechanism for the skill's functionality.\n- [EXTERNAL_DOWNLOADS]: The instructions direct the user to install and run the@membranehq/clipackage from NPM. This is a legitimate tool provided by the vendor for interacting with their platform.\n- [PROMPT_INJECTION]: The skill processes data from external websites via WebScraping.AI. This presents an indirect prompt injection surface where instructions in scraped content could potentially be seen by the agent, though no active exploitation is present in the skill itself.
Audit Metadata