webmcp-user-interaction

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to ingest external content without providing safety instructions.
  • Ingestion points: The agent is directed to use WebFetch to retrieve documentation from https://webmachinelearning.github.io/webmcp/ and WebSearch to find community patterns.
  • Boundary markers: There are no instructions to the agent to treat external content as untrusted or to use delimiters to separate it from system instructions.
  • Capability inventory: The skill has access to powerful tools including Bash, Write, and Edit, which could be abused if malicious instructions were encountered in search results or documentation.
  • Sanitization: The instructions lack guidance on sanitizing or validating external data before it is processed or used in subsequent tool calls.
  • [EXTERNAL_DOWNLOADS]: The skill fetches implementation documentation from the Web Machine Learning GitHub Pages site (webmachinelearning.github.io) to provide the agent with technical context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM