web-article-translator
Pass
Audited by Gen Agent Trust Hub on May 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches and processes untrusted content from external URLs. Maliciously crafted articles could attempt to bypass the agent's instructions during the translation or saving process.\n
- Ingestion points: The
mcp__web_reader__webReadertool fetches content from user-provided external URLs.\n - Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the article text.\n
- Capability inventory: The skill instructs the agent to write files to the local directory, providing a path for potential unauthorized file creation if the agent follows instructions from the article content.\n
- Sanitization: There is no evidence of sanitization or filtering applied to the fetched content before it is processed for translation.
Audit Metadata