web-search

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data from web searches and page scraping via the web_search_web_search and webcontext_scrape tools. It includes specific defensive instructions to treat retrieved content as data, not instructions, and to avoid executing operations not present in the authoritative schema.
  • [EXTERNAL_DOWNLOADS]: The skill references a production MCP endpoint at https://mcp.replynodes.com/mcp. This is a vendor-owned resource managed by ReplyNodes and is consistent with the skill's stated purpose.
  • [CREDENTIALS_UNSAFE]: The skill requires a REPLYNODES_API_KEY. The instructions follow security best practices by directing the agent to access the key from a secure secret store and forbidding its exposure in logs or prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:04 PM
Security Audit — agent-trust-hub — web-search