parallel-web-search
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a command-line interface tool (
parallel-cli) to perform web searches and manage service balances. - Evidence: Found in
SKILL.mdusing theBashtool to runparallel-cli searchandparallel-cli balancecommands. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external content from the web, which creates a surface for potential indirect instructions embedded in search results.
- Ingestion points: External web content is fetched via
parallel-cliand saved to temporary JSON files in/tmp/before being read by the agent. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" tags for the retrieved search result excerpts.
- Capability inventory: The agent has access to the
Bashtool and can write to the local file system (/tmp/). - Sanitization: No explicit sanitization or filtering of the retrieved web content is specified before the agent synthesizes its response.
Audit Metadata