octoparse-ultimate-scraper
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill establishes a large surface for indirect prompt injection due to its primary function of scraping and reporting data from arbitrary external websites. Maliciously crafted content on target websites could attempt to influence the agent's behavior during the summarization or reporting phase.
- Ingestion points: Scraped data retrieved via the
export_datatool and external files downloaded usingdirectAccesslinks (found inSKILL.mdandreferences/gotchas.md). - Boundary markers: The instructions do not prescribe specific delimiters or safety warnings for the agent when reporting the scraped content back to the user.
- Capability inventory: The agent has access to tools for starting/stopping tasks (
start_or_stop_task), executing new tasks (execute_task), and performing shell commands via thecurlTemplatemechanism. - Sanitization: No explicit content filtering or escaping requirements are defined for the processed data.
- [COMMAND_EXECUTION]: The workflow for handling large result sets (50+ rows) directs the agent to execute a
curlTemplateprovided dynamically in the response from theexport_datatool. While this is a functional requirement for retrieving data from the vendor's infrastructure (Octoparse), it involves the agent executing shell commands generated at runtime by a remote service.
Audit Metadata