scavio
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Mentions official vendor packages including
scavioandlangchain-scaviofor language-specific integration. - [INDIRECT_PROMPT_INJECTION]: The skill provides an interface to scrape data from 50+ third-party platforms, which exposes the agent to instructions potentially embedded in untrusted web content.
- Ingestion points: Responses from
api.scavio.devcontaining content from external sites. - Boundary markers: Instruction templates do not include specific delimiters to isolate scraped text.
- Capability inventory: Data fetching capabilities via API endpoints.
- Sanitization: Data is provided in structured JSON format, but textual values within the payload are not sanitized for injection patterns.
Audit Metadata