buy or bounce
Pass
Audited by Gen Agent Trust Hub on Jun 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches content from external URLs provided by the user to perform its analysis. This is a core functional requirement and is triggered only by user input.
- [COMMAND_EXECUTION]: The skill generates and writes an HTML report to the local file system in the user's output directory. This behavior is the intended delivery mechanism for the skill's findings.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from URLs or pasted text (Ingestion points: landing page text or URL; Boundary markers: absent; Capability inventory: URL fetching and local file writing; Sanitization: absent). This is an inherent risk factor of the skill's primary function.
Audit Metadata