web-article-translator

Pass

Audited by Gen Agent Trust Hub on May 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches and processes untrusted content from external URLs. Maliciously crafted articles could attempt to bypass the agent's instructions during the translation or saving process.\n
  • Ingestion points: The mcp__web_reader__webReader tool fetches content from user-provided external URLs.\n
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the article text.\n
  • Capability inventory: The skill instructs the agent to write files to the local directory, providing a path for potential unauthorized file creation if the agent follows instructions from the article content.\n
  • Sanitization: There is no evidence of sanitization or filtering applied to the fetched content before it is processed for translation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 3, 2026, 12:14 AM