parallel-web-extract

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command parallel-cli extract "$ARGUMENTS". Although the arguments are wrapped in double quotes, if the user-supplied URLs in $ARGUMENTS contain shell metacharacters and the agent or platform does not perform strict sanitization, it could lead to command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant vulnerability surface for indirect prompt injection:
  • Ingestion points: Data is fetched from arbitrary external URLs provided by the user via the parallel-cli extract command.
  • Boundary markers: Absent. There are no instructions or delimiters (like XML tags or specific 'ignore' markers) to help the agent distinguish between the extracted data and its own system instructions.
  • Capability inventory: The skill has access to the Bash tool, allowing it to execute commands and write JSON output to the /tmp directory.
  • Sanitization: Absent. The instructions explicitly command the agent to keep content "verbatim" and "preserve all facts, names, numbers, dates, quotes," which ensures that any malicious instructions hidden on a webpage are presented directly to the agent's context without modification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:25 PM
Security Audit — agent-trust-hub — parallel-web-extract