skills/simota/agent-skills/vector/Gen Agent Trust Hub

vector

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is primarily designed to scrape and process arbitrary web pages, creating a significant attack surface for indirect prompt injection where malicious instructions embedded in web content could influence the agent's behavior.
  • Ingestion points: Web page content is ingested via playwright_snapshot, get_page_text, and network response monitoring.
  • Boundary markers: The skill mentions _common/WEB_FETCH_SAFETY.md for prompt-injection checks before content is summarized or relayed.
  • Capability inventory: The skill possesses extensive capabilities including writing to the .vector/ directory, making network requests via Playwright, and executing code through playwright_evaluate and browser_run_code.
  • Sanitization: While safety checks are mentioned, the inherent nature of processing untrusted HTML/DOM content is a persistent risk.
  • [DYNAMIC_EXECUTION]: The skill utilizes tools that allow for the execution of arbitrary code within the browser context.
  • Evidence: playwright_evaluate is used to execute JavaScript (e.g., to pierce Shadow DOM or perform complex extractions), and browser_run_code allows the execution of Playwright scripts directly.
  • Risk: If the agent generates these scripts based on untrusted input from a web page, it could lead to code execution within the browser environment.
  • [COMMAND_EXECUTION]: The skill documentation encourages the use of the Playwright CLI over the MCP server for multi-step tasks to save tokens.
  • Evidence: Mentions in SKILL.md and reference/computer-use-optimization.md explicitly advocate for the CLI path when filesystem access is available.
  • [EXTERNAL_DOWNLOADS]: The skill references a wide range of external tools and services for specialized tasks like stealth scraping and large-scale crawling.
  • Evidence: Mentions of curl-impersonate, bright-data, oxylabs, and CAPTCHA solving services like 2Captcha or Anti-Captcha in reference/stealth-mode.md and reference/crawl/anti-detection-architecture.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — vector