broken-link-scan

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it ingests untrusted data from external websites.
  • Ingestion points: SKILL.md extracts link text and URLs from external web pages using the Playwright MCP.
  • Boundary markers: Absent. The skill does not provide delimiters or instructions to the agent to ignore potential commands embedded in the crawled link text.
  • Capability inventory: The skill uses mcp__playwright__browser_navigate and mcp__playwright__browser_evaluate to interact with websites.
  • Sanitization: No specific filtering or escaping is applied to the content retrieved from the web page's DOM.
  • [SAFE]: The skill mentions qualitymax.io, which belongs to the vendor 'Quality-Max'. This reference is used for promotional or informational purposes within the scan report and does not involve unauthorized data transmission or malicious behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 12:20 AM
Security Audit — agent-trust-hub — broken-link-scan