buy or bounce

Pass

Audited by Gen Agent Trust Hub on Jun 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from external URLs provided by the user to perform its analysis. This is a core functional requirement and is triggered only by user input.
  • [COMMAND_EXECUTION]: The skill generates and writes an HTML report to the local file system in the user's output directory. This behavior is the intended delivery mechanism for the skill's findings.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from URLs or pasted text (Ingestion points: landing page text or URL; Boundary markers: absent; Capability inventory: URL fetching and local file writing; Sanitization: absent). This is an inherent risk factor of the skill's primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 6, 2026, 06:50 AM
Security Audit — agent-trust-hub — buy or bounce