paw-mkt-video

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions in 'references/shared-patterns.md' to install the 'agent-browser' tool from the official GitHub repository of a trusted organization (Vercel Labs). This is a legitimate dependency for the skill's research capabilities.
  • [COMMAND_EXECUTION]: The skill executes local setup and discovery scripts ('tool-discovery.sh', 'chrome-profiles.sh') and utilizes the 'agent-browser' CLI. These operations are intended for environment configuration and research within a controlled automation context.
  • [PROMPT_INJECTION]: The skill processes untrusted content from user-provided URLs for audits as described in 'references/shared-patterns.md'. This represents an indirect prompt injection surface. The ingestion point is the live URL audit feature; capability inventory includes browser-based research and file writes to specific project paths; boundary markers and sanitization are not explicitly defined in the static instructions. This risk is inherent to the skill's primary research purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 10:38 AM
Security Audit — agent-trust-hub — paw-mkt-video