documentation-scraper

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill explicitly instructs the agent to run commands outside the security sandbox using dangerouslyDisableSandbox: true. This is requested to allow the network and file system access necessary for web scraping, but it bypasses standard security boundaries.
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to install the slurp-ai package globally via npm install -g slurp-ai. This introduces an external dependency that executes with full user permissions.
  • [COMMAND_EXECUTION]: The skill relies on executing the slurp binary and a local script analyze-sitemap.js to perform its core functions of network crawling and file compilation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest large amounts of documentation from external websites into the agent's context. This creates a significant surface for indirect prompt injection.
  • Ingestion points: Content is fetched from arbitrary URLs via the slurp command and stored in slurp_compiled/compiled_docs.md.
  • Boundary markers: None are specified in the skill to delimit the scraped content or warn the agent about potentially malicious instructions within the documentation.
  • Capability inventory: The skill uses slurp for network requests and file writing, and node to execute the analyze-sitemap.js utility script.
  • Sanitization: The skill does not mention any sanitization or filtering of the scraped markdown content before it is provided to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:09 PM
Security Audit — agent-trust-hub — documentation-scraper