paw-mkt-sales
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Recommends installing the
agent-browsertool from Vercel Labs' official GitHub repository andplaywrightvianpxto enable live web research. - [COMMAND_EXECUTION]: Provides instructions for environment setup, tool discovery, and browser automation sessions. This includes scripts for discovering browser profiles and managing authenticated sessions for research on platforms like LinkedIn.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it processes untrusted data from external websites. • Ingestion points: Extracts body text from external competitor sites and review platforms like G2 as documented in
references/competitive-research.md. • Boundary markers: Absent. The instructions do not define delimiters or provide warnings to ignore potential instructions embedded within the fetched web content. • Capability inventory: The skill possesses the ability to execute shell commands viaagent-browserand write deliverables to the local filesystem (documented inSKILL.mdandreferences/workflow.md). • Sanitization: Absent. Content fetched from external URLs is not validated or sanitized before being incorporated into the agent's context.
Audit Metadata