mixed-content-scan

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks because it ingests and processes data from external websites. \n- Ingestion points: Untrusted data enters the agent context through the mcp__playwright__browser_navigate and DOM inspection steps described in SKILL.md. \n- Boundary markers: None; the skill lacks delimiters or specific instructions to the agent to ignore commands potentially embedded in the scanned content. \n- Capability inventory: The skill employs mcp__playwright tools which allow for browser navigation and network request logging. \n- Sanitization: None; website content is analyzed as-is without validation or escaping techniques to mitigate prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 04:07 PM
Security Audit — agent-trust-hub — mixed-content-scan