paw-mkt-sales

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends installing the agent-browser tool from Vercel Labs' official GitHub repository and playwright via npx to enable live web research.
  • [COMMAND_EXECUTION]: Provides instructions for environment setup, tool discovery, and browser automation sessions. This includes scripts for discovering browser profiles and managing authenticated sessions for research on platforms like LinkedIn.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it processes untrusted data from external websites. • Ingestion points: Extracts body text from external competitor sites and review platforms like G2 as documented in references/competitive-research.md. • Boundary markers: Absent. The instructions do not define delimiters or provide warnings to ignore potential instructions embedded within the fetched web content. • Capability inventory: The skill possesses the ability to execute shell commands via agent-browser and write deliverables to the local filesystem (documented in SKILL.md and references/workflow.md). • Sanitization: Absent. Content fetched from external URLs is not validated or sanitized before being incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 07:42 AM