web-browsing-cli
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npxto execute the@only-cli/ocpackage, which is a vendor-owned resource. - [COMMAND_EXECUTION]: The skill relies on shell command execution to perform web browsing, site searches, and session state management.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web content from arbitrary URLs, presenting a surface for indirect prompt injection.
- Ingestion points: External web content retrieved through various extraction commands in SKILL.md.
- Boundary markers: The documentation includes an explicit safety warning in the Untrusted content section to treat ingested text as data rather than instructions.
- Capability inventory: Shell execution capabilities via
npxand local filesystem access for session storage in ~/.only-cli/sessions/. - Sanitization: The tool converts complex HTML into a simplified, token-efficient terminal format, which helps reduce injection surface.
Audit Metadata