web-search
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data from web searches and page scraping via the
web_search_web_searchandwebcontext_scrapetools. It includes specific defensive instructions to treat retrieved content as data, not instructions, and to avoid executing operations not present in the authoritative schema. - [EXTERNAL_DOWNLOADS]: The skill references a production MCP endpoint at
https://mcp.replynodes.com/mcp. This is a vendor-owned resource managed by ReplyNodes and is consistent with the skill's stated purpose. - [CREDENTIALS_UNSAFE]: The skill requires a
REPLYNODES_API_KEY. The instructions follow security best practices by directing the agent to access the key from a secure secret store and forbidding its exposure in logs or prompts.
Audit Metadata