scraping
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses well-known technology services and standard tools for its intended purpose. No malicious commands, obfuscation, or unauthorized data access patterns were found in the skill content.\n- [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from the web, creating a potential surface for indirect prompt injection.\n
- Ingestion points: Data is fetched from external websites using
WebFetch,Firecrawl, orBright Datatools as specified in the SKILL.md file.\n - Boundary markers: The skill does not define specific delimiters or security instructions to prevent the agent from executing commands embedded in the scraped content.\n
- Capability inventory: The skill allows access to the
BashandWritetools, which are high-capability tools that could be abused if the agent obeys instructions found in external scraped data.\n - Sanitization: There are no documented steps for validating or sanitizing the content retrieved from external sources before processing.
Audit Metadata