cloning-websites-to-weaverse

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches content from arbitrary external URLs provided by the user. This data is then used to drive code generation and design specifications, which creates a surface where a malicious source website could include instructions designed to influence the agent's behavior.
    • Ingestion points: Scraped content output from Firecrawl saved to the .firecrawl/ directory.
    • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' directives when the agent processes the untrusted scraped data.
    • Capability inventory: The agent has the ability to write new source files (app/routes/clone-preview.$page.tsx) and execute CLI commands.
    • Sanitization: No sanitization or filtering logic is described for the scraped HTML or Markdown before it is consumed by the agent for generation tasks.
  • [DYNAMIC_EXECUTION]: The workflow requires the agent to generate a Hydrogen/React route file (app/routes/clone-preview.$page.tsx) that implements the visual structure and content of the scraped origin site. This involves translating untrusted external content into executable code that is then rendered within the development environment.
  • [COMMAND_EXECUTION]: The skill explicitly utilizes shell commands (firecrawl scrape and firecrawl crawl) to perform its primary data acquisition tasks.
  • [EXTERNAL_DOWNLOADS]: The skill workflow is centered around fetching and downloading layout and content data from arbitrary external websites via the Firecrawl scraping service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:16 PM
Security Audit — agent-trust-hub — cloning-websites-to-weaverse