webmcp-gen

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Dynamic Script Generation: The workflow involves generating a webmcp.init.js file and executing it within a browser environment using the agent-browser tool. This pattern is central to the skill's purpose of tool creation and testing.
  • Handling Untrusted Web Data: The skill interacts with external web pages to derive tool definitions and schemas. The instructions include a specific safety section advising the agent to treat all page-derived content as untrusted, which helps mitigate risks associated with indirect prompt injection from processed web data.
  • Command Line Interaction: The skill utilizes the agent-browser command-line utility to perform actions like opening URLs and invoking tools. This is standard behavior for the intended development and automation tasks, scoped to the browser environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 09:37 AM
Security Audit — agent-trust-hub — webmcp-gen