webmcp-declarative-forms
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from external, untrusted sources which could potentially contain malicious instructions targeting the agent's broad toolset.
- Ingestion points: Instructions in
SKILL.mdto fetch documentation fromhttps://webmachinelearning.github.io/webmcp/and perform multiple web searches on Google and Chrome developer sites. - Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded within the fetched documentation or search results.
- Capability inventory: The skill has access to sensitive tools including
Bash,Write,Edit,Grep,Glob, andWebFetchacross its execution environment. - Sanitization: There are no explicit instructions for the agent to sanitize or validate the external content before using it to guide code generation or system operations.
Audit Metadata