site-audit

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection as it is designed to ingest and process content from external websites.\n
  • Ingestion points: Tools such as firecrawl_crawl, context_dev_scrape_markdown, and context_dev_scrape_html retrieve content from third-party URLs into the agent context (SKILL.md, references/sandbase-api-map.md).\n
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious content embedded in the scraped data.\n
  • Capability inventory: The skill uses sandbase_call_tool to perform web crawling, mapping, and visual assessments; it does not appear to have access to sensitive local files or shell execution.\n
  • Sanitization: There are no explicit instructions for sanitizing or filtering the content retrieved from external sites.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — site-audit