is-agentic

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Indirect Prompt Injection: The skill ingests data from external audit reports produced by auditing third-party websites. These reports contain recommendations and details derived from the audited content, which could potentially be used to influence the agent's actions during the remediation process.
  • Ingestion points: Audit reports are fetched via the is-agentic CLI or retrieved from the is-agentic.com API.
  • Boundary markers: The skill instructions do not define specific delimiters or markers to isolate the external audit report content from the agent's core instructions.
  • Capability inventory: The skill utilizes npx for audits and is intended to help fix technical website issues, which may involve modifying project files.
  • Sanitization: The instructions do not specify any validation or sanitization of the audit report content before the agent acts on the recommendations.
  • External Package Execution: The skill facilitates the execution of the is-agentic utility via npx or bunx. This downloads and runs the package from the official Node.js registry as part of its auditing process.
  • Network Communication: The skill performs requests to is-agentic.com to retrieve audit results and developer documentation. This is a standard and documented operation for fetching the technical data required by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 12:27 PM
Security Audit — agent-trust-hub — is-agentic