cloning-websites-to-weaverse
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches content from arbitrary external URLs provided by the user. This data is then used to drive code generation and design specifications, which creates a surface where a malicious source website could include instructions designed to influence the agent's behavior.
- Ingestion points: Scraped content output from Firecrawl saved to the
.firecrawl/directory. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' directives when the agent processes the untrusted scraped data.
- Capability inventory: The agent has the ability to write new source files (
app/routes/clone-preview.$page.tsx) and execute CLI commands. - Sanitization: No sanitization or filtering logic is described for the scraped HTML or Markdown before it is consumed by the agent for generation tasks.
- Ingestion points: Scraped content output from Firecrawl saved to the
- [DYNAMIC_EXECUTION]: The workflow requires the agent to generate a Hydrogen/React route file (
app/routes/clone-preview.$page.tsx) that implements the visual structure and content of the scraped origin site. This involves translating untrusted external content into executable code that is then rendered within the development environment. - [COMMAND_EXECUTION]: The skill explicitly utilizes shell commands (
firecrawl scrapeandfirecrawl crawl) to perform its primary data acquisition tasks. - [EXTERNAL_DOWNLOADS]: The skill workflow is centered around fetching and downloading layout and content data from arbitrary external websites via the Firecrawl scraping service.
Audit Metadata