content-harvest

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute multiple shell commands, including curl, sed, grep, and tr. It interpolates user-provided URLs directly into these commands, which could lead to command injection if the execution environment does not properly sanitize shell arguments.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing third-party packages at runtime using npm install -g @mozilla/readability-cli, npm install -g reader-cli, and pip3 install trafilatura. These are external dependencies that modify the agent's execution environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by design.
  • Ingestion points: Content is fetched from arbitrary external URLs provided by the user using curl, reader, or trafilatura (SKILL.md).
  • Boundary markers: The skill does not use specific delimiters or instructions to the agent to ignore potentially malicious commands embedded within the extracted article text.
  • Capability inventory: The agent has the ability to execute shell commands, install software, write to the filesystem, and preview file contents.
  • Sanitization: While filenames are cleaned for filesystem compatibility, the article content itself is not sanitized or filtered for instructions that might target the agent.
  • [DYNAMIC_EXECUTION]: The skill uses python3 -c to execute an inline Python script for HTML parsing. While the script is static within the skill instructions, it dynamically processes untrusted data fetched from the network.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — content-harvest