agent-deepweb

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill teaches the agent how to execute the agent-deepweb CLI tool. The commands are scoped to information gathering (profile list, usage), authenticated requests (fetch, graphql), and auditing (audit show).
  • [EXTERNAL_DOWNLOADS]: The skill references a GitHub repository for the agent-deepweb tool (github.com/shhac/agent-deepweb). As this belongs to the skill author's infrastructure and is provided for informational purposes regarding tool installation, it is considered a legitimate resource.
  • [CREDENTIALS_SAFE]: The skill emphasizes secret management by using named profiles where actual values remain hidden from the agent. It explicitly warns against handling raw tokens and explains that sensitive values in responses are redacted by the underlying tool.
  • [PRIVILEGE_ESCALATION]: The documentation includes a 'Deny' list for the agent harness, recommending that administrative or destructive commands (like adding profiles, changing allowlists, or unmasking secrets) be restricted and require user-supplied passphrases.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 09:40 PM
Security Audit — agent-trust-hub — agent-deepweb