webmcp-user-interaction
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by instructing the agent to ingest external content without providing safety instructions.
- Ingestion points: The agent is directed to use
WebFetchto retrieve documentation fromhttps://webmachinelearning.github.io/webmcp/andWebSearchto find community patterns. - Boundary markers: There are no instructions to the agent to treat external content as untrusted or to use delimiters to separate it from system instructions.
- Capability inventory: The skill has access to powerful tools including
Bash,Write, andEdit, which could be abused if malicious instructions were encountered in search results or documentation. - Sanitization: The instructions lack guidance on sanitizing or validating external data before it is processed or used in subsequent tool calls.
- [EXTERNAL_DOWNLOADS]: The skill fetches implementation documentation from the Web Machine Learning GitHub Pages site (
webmachinelearning.github.io) to provide the agent with technical context.
Audit Metadata