website
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill describes a workflow for scraping existing websites (specifically those built on Wix) using browser automation tools. This creates an attack surface for indirect prompt injection, where malicious instructions hidden in a third-party website's content could influence the agent's behavior.
- Ingestion points: The section 'Scraping & Rebuilding Existing Sites' directs the agent to use browser tools like
get_page_textandjavascript_toolon external, untrusted URLs. - Boundary markers: The instructions do not define clear boundaries or 'ignore' directives to prevent the agent from following instructions embedded within the scraped content.
- Capability inventory: The skill possesses the ability to execute network requests, run JavaScript, and write files to the local environment.
- Sanitization: No explicit sanitization or filtering of the scraped content is mandated before the data is processed by the agent.
- [COMMAND_EXECUTION]: The skill provides instructions for deploying website files to the Netlify API using shell commands like
zipandcurl. - Evidence: The 'Deployment (Netlify via API)' section provides a script to bundle files and transmit them to
api.netlify.com. - [DATA_EXFILTRATION]: The skill establishes a pattern for using API tokens to authenticate with remote services. While it uses placeholders, the workflow involves transmitting sensitive authentication material to a remote endpoint.
- Evidence: The deployment scripts demonstrate the use of a
NETLIFY_TOKENvariable to authorize network requests to external infrastructure.
Audit Metadata