web-scraper

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external websites via various tools such as context_dev_scrape_markdown and firecrawl_scrape. This introduces an attack surface for indirect prompt injection, where an external webpage could contain malicious instructions intended to mislead the agent.
  • Ingestion points: External website content retrieved by scraping and crawling tools in SKILL.md and references/sandbase-api-map.md.
  • Boundary markers: The instructions do not define specific delimiters for separating untrusted web content from agent instructions.
  • Capability inventory: The skill itself does not define direct subprocess execution or file system writes, relying instead on API calls to the SandBase gateway.
  • Sanitization: The instructions do not specify sanitization or filtering protocols for the ingested content.
  • [SAFE]: The tools referenced, including the context_dev series and firecrawl suite, are consistent with the skill's stated purpose of web scraping and data extraction. The context_dev tools belong to the author's (sandbaseai) own service ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — web-scraper