paw-mkt-pricing

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the agent-browser automation tool from the Vercel Labs official GitHub organization, which is a trusted source.
  • [COMMAND_EXECUTION]: Leverages shell commands (e.g., npm, npx, node) for environmental discovery and setting up automation workflows. It also uses the agent-browser CLI to perform interactive research tasks.
  • [REMOTE_CODE_EXECUTION]: Includes instructions for adding remote agent capabilities via npx skills add specifically targeting verified and well-known software repositories.
  • [DATA_EXFILTRATION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from the open web during competitive research. It possesses the capability to write this data to local files and use it to inform strategy. However, it provides clear documentation on managing sensitive browser authentication states and session tokens to prevent accidental exposure.
  • [SAFE]: All external resource dependencies and tool references originate from the vendor's own infrastructure or established, trusted technology providers.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 10:37 AM
Security Audit — agent-trust-hub — paw-mkt-pricing