webmcp-security
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates a workflow that fetches documentation from external sources, which creates a potential surface for indirect prompt injection where malicious content in a fetched page could attempt to influence the agent.
- Ingestion points: Retrieval of documentation from 'webmachinelearning.github.io' and general web search results.
- Boundary markers: The skill does not define specific delimiters or instructions to the agent to ignore directives found within the retrieved content.
- Capability inventory: The agent is permitted to use sensitive tools such as 'Bash', 'Write', and 'Edit', which increases the potential impact of an injection.
- Sanitization: There is no explicit mention of sanitizing or validating the fetched documentation or search results before they are processed by the agent.
Audit Metadata