agent-deepweb
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill teaches the agent how to execute the
agent-deepwebCLI tool. The commands are scoped to information gathering (profile list,usage), authenticated requests (fetch,graphql), and auditing (audit show). - [EXTERNAL_DOWNLOADS]: The skill references a GitHub repository for the
agent-deepwebtool (github.com/shhac/agent-deepweb). As this belongs to the skill author's infrastructure and is provided for informational purposes regarding tool installation, it is considered a legitimate resource. - [CREDENTIALS_SAFE]: The skill emphasizes secret management by using named profiles where actual values remain hidden from the agent. It explicitly warns against handling raw tokens and explains that sensitive values in responses are redacted by the underlying tool.
- [PRIVILEGE_ESCALATION]: The documentation includes a 'Deny' list for the agent harness, recommending that administrative or destructive commands (like adding profiles, changing allowlists, or unmasking secrets) be restricted and require user-supplied passphrases.
Audit Metadata