documentation-scraper
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill explicitly instructs the agent to run commands outside the security sandbox using
dangerouslyDisableSandbox: true. This is requested to allow the network and file system access necessary for web scraping, but it bypasses standard security boundaries. - [EXTERNAL_DOWNLOADS]: The skill directs the user to install the
slurp-aipackage globally vianpm install -g slurp-ai. This introduces an external dependency that executes with full user permissions. - [COMMAND_EXECUTION]: The skill relies on executing the
slurpbinary and a local scriptanalyze-sitemap.jsto perform its core functions of network crawling and file compilation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest large amounts of documentation from external websites into the agent's context. This creates a significant surface for indirect prompt injection.
- Ingestion points: Content is fetched from arbitrary URLs via the
slurpcommand and stored inslurp_compiled/compiled_docs.md. - Boundary markers: None are specified in the skill to delimit the scraped content or warn the agent about potentially malicious instructions within the documentation.
- Capability inventory: The skill uses
slurpfor network requests and file writing, andnodeto execute theanalyze-sitemap.jsutility script. - Sanitization: The skill does not mention any sanitization or filtering of the scraped markdown content before it is provided to the agent.
Audit Metadata