url-to-markdown
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process content from any public web page, which introduces an attack surface for instructions embedded in external data.
- Ingestion points: The tools
strale_url_to_markdownandcontext_dev_scrape_markdowningest content from arbitrary URLs provided by the user or found during research. - Boundary markers: The instructions do not specify the use of delimiters or clear separation between the agent's instructions and the untrusted content retrieved from the web.
- Capability inventory: The agent context involves synthesizing findings and citations based on the ingested Markdown content, which could lead the agent to follow instructions hidden in that content.
- Sanitization: There is no evidence of content sanitization or filtering to remove potential prompt injection payloads from the scraped Markdown.
Audit Metadata