dns-connector

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from an external website, which creates a potential surface for indirect prompt injection attacks.
  • Ingestion points: Untrusted data enters the agent's context from the dns-shop.ru website via the dns_search and dns_card tools.
  • Boundary markers: The documentation does not specify the use of delimiters or instructions to the agent to ignore any commands that might be embedded within the scraped product data.
  • Capability inventory: The skill is capable of rendering web pages and extracting data from the DOM using the Chrome DevTools Protocol (CDP).
  • Sanitization: There is no evidence in the skill description of sanitization, filtering, or validation performed on the retrieved content before it is provided to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:00 PM
Security Audit — agent-trust-hub — dns-connector