paw-mkt-community
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes browser automation (agent-browser) for auditing live community URLs and conducting market research. It provides explicit security instructions for managing authenticated sessions safely, such as using dedicated profiles and adding authentication state files to .gitignore.
- [SAFE]: External dependencies and remote tools are restricted to well-known services and trusted organizations. For instance, it recommends the agent-browser skill from the Vercel Labs repository on GitHub.
- [SAFE]: The skill implements a structured workflow that involves reading local project configuration and marketing context files. This behavior is consistent with its stated purpose of providing brand-aligned community management services.
- [SAFE]: No patterns of prompt injection, data exfiltration, or code obfuscation were found across the skill's instructions or its extensive library of reference frameworks.
- [SAFE]: The skill has an indirect prompt injection surface as it audits live URLs, but this is handled using standard browser automation capabilities without excessive privilege. Ingestion points: Live community URLs and public websites accessed via the Context Router in references/shared-patterns.md. Capability inventory: Uses agent-browser to interact with websites and has file-write capabilities for saving deliverables to the local project structure. No specific sanitization logic is defined, which is standard for research tools of this type.
Audit Metadata