compare-to-notte-costs

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its processing of untrusted data from multiple sources. Ingestion points: local source code, telemetry logs, and invoices (SKILL.md). Boundary markers: No specific delimiters or safety instructions are defined for when the agent reads these external files. Capability inventory: The skill can read arbitrary files in the repository and execute vendor CLI commands. Sanitization: There is no requirement for the agent to filter the ingested data.
  • [DATA_EXFILTRATION]: The skill audits sensitive financial and operational data, including invoices and telemetry. While the data is intended for local reporting, this functionality requires access to confidential business information.
  • [COMMAND_EXECUTION]: The skill runs environment verification checks using vendor-provided tools, specifically notte version and notte auth status.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves data from third-party sources such as browserarena.ai for benchmarks and various browser automation provider pricing pages to conduct its cost comparison.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:54 AM
Security Audit — agent-trust-hub — compare-to-notte-costs