paw-mkt-analytics

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the agent-browser tool from the official vercel-labs GitHub repository, which is a trusted source.
  • [COMMAND_EXECUTION]: Shell commands are used for environment setup, tool installation, and browser automation tasks. This includes executing local scripts from the vendor's own setup suite.
  • [DATA_EXFILTRATION]: The skill includes guidance on capturing and using authenticated browser session states stored in local JSON files. While it provides explicit warnings to exclude these files from version control, the handling of plaintext session tokens presents a risk of credential exposure.
  • [PROMPT_INJECTION]: The skill's web auditing functionality creates an attack surface for indirect prompt injection. Ingestion points: Content is retrieved from live websites via agent-browser and WebFetch (shared-patterns.md). Boundary markers: The instructions do not define delimiters or explicit 'ignore' directives for processing untrusted web content. Capability inventory: The skill can execute shell commands and perform project-level file writes. Sanitization: No mechanisms for content validation or sanitization are specified for ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 10:38 AM
Security Audit — agent-trust-hub — paw-mkt-analytics