webmcp-cli-skill
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install the
@opentiny/webmcp-clipackage globally via npm. This is the core utility for the skill's functionality and is provided by the skill author. - [COMMAND_EXECUTION]: The skill operates by executing various shell commands to control browser tabs and interact with page-specific tools. This includes managing browser state, opening URLs, and running automated tasks on supported domains like CSDN, Juejin, and Excalidraw.
- [DYNAMIC_EXECUTION]: The
page-agent-toolincludes anexecuteJavascriptaction that permits the AI agent to run arbitrary JavaScript code within the context of the current browser page. This is a highly capable feature intended for advanced page automation. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and analyzes content from external websites (via
browserStateandsearchTree) which constitutes an attack surface where malicious web content could influence the agent's behavior. - Ingestion points: Web content and ARIA trees retrieved from any website navigated to by the agent using the
webmcp-clitool (specifically in SKILL.md and page-agent-tool descriptions). - Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions for the content retrieved from external DOM/Aria trees.
- Capability inventory: The agent can perform browser navigation, click elements, fill forms, scroll pages, and execute JavaScript (detailed in SKILL.md and domains/ guides).
- Sanitization: There are no documented sanitization or filtering steps applied to the web content before it is processed by the AI agent.
Audit Metadata