fetch-website-content
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill requires transforming all target URLs by prepending 'https://markdown.new/'. This routes the agent's web requests through a third-party service, exposing the target URL and its structure to that provider. While the skill warns against using it for private sites, the request itself can leak information such as internal directory structures or metadata contained in the URL.
- [EXTERNAL_DOWNLOADS]: The skill depends on an external, third-party service ('markdown.new') for its primary functionality of content conversion and processing. Reliance on an external service whose data handling and security practices are not defined within the skill presents a supply chain risk.
- [PROMPT_INJECTION]: This skill provides a surface for indirect prompt injection by fetching untrusted external content and asking the agent to analyze it. This creates a risk where instructions embedded in the target webpage could influence the agent's behavior.
- Ingestion points: External content fetched via the proxy service (SKILL.md, 'Lookup Process' section).
- Boundary markers: Absent; there are no instructions to use delimiters or specific ignore-embedded-instruction warnings for the fetched content.
- Capability inventory: The agent is instructed to use the fetched content for analysis and response generation.
- Sanitization: Absent; the skill does not instruct the agent to sanitize, validate, or escape the content fetched from the web before processing it.
Audit Metadata