webmcp-declarative-forms

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from external, untrusted sources which could potentially contain malicious instructions targeting the agent's broad toolset.
  • Ingestion points: Instructions in SKILL.md to fetch documentation from https://webmachinelearning.github.io/webmcp/ and perform multiple web searches on Google and Chrome developer sites.
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded within the fetched documentation or search results.
  • Capability inventory: The skill has access to sensitive tools including Bash, Write, Edit, Grep, Glob, and WebFetch across its execution environment.
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the external content before using it to guide code generation or system operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM