parallel-web-extract
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command
parallel-cli extract "$ARGUMENTS". Although the arguments are wrapped in double quotes, if the user-supplied URLs in$ARGUMENTScontain shell metacharacters and the agent or platform does not perform strict sanitization, it could lead to command injection. - [INDIRECT_PROMPT_INJECTION]: The skill has a significant vulnerability surface for indirect prompt injection:
- Ingestion points: Data is fetched from arbitrary external URLs provided by the user via the
parallel-cli extractcommand. - Boundary markers: Absent. There are no instructions or delimiters (like XML tags or specific 'ignore' markers) to help the agent distinguish between the extracted data and its own system instructions.
- Capability inventory: The skill has access to the
Bashtool, allowing it to execute commands and write JSON output to the/tmpdirectory. - Sanitization: Absent. The instructions explicitly command the agent to keep content "verbatim" and "preserve all facts, names, numbers, dates, quotes," which ensures that any malicious instructions hidden on a webpage are presented directly to the agent's context without modification.
Audit Metadata