skills/slooowshutter/skills/dogfood/Gen Agent Trust Hub

dogfood

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it is designed to navigate to and analyze untrusted external web content.
  • Ingestion points: The skill uses browser_navigate, browser_snapshot, and browser_vision to ingest data from user-provided target URLs in SKILL.md.
  • Boundary markers: There are no instructions or delimiters in the skill files that direct the agent to ignore or isolate commands found within the web pages being tested.
  • Capability inventory: The skill allows the agent to interact with the target pages via browser_click, browser_type, and browser_press, and it writes reports and screenshots to the local filesystem using templates provided in templates/dogfood-report-template.md.
  • Sanitization: No evidence of content validation or sanitization is present before the agent processes the retrieved data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:48 PM
Security Audit — agent-trust-hub — dogfood