terms-of-service-generator

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill uses the WebFetch tool to ingest and analyze untrusted content from external websites. A malicious website could contain instructions designed to influence the agent's behavior or output during the document generation phase.
  • Ingestion points: Step 1 instructions direct the agent to use WebFetch on a user-provided URL to analyze business details.
  • Boundary markers: The instructions do not define clear boundaries or 'ignore' directives for the content retrieved from the web, making the agent susceptible to embedded instructions.
  • Capability inventory: The skill includes file writing capabilities, creating a markdown file with the generated Terms of Service in the local directory.
  • Sanitization: There is no explicit sanitization, filtering, or validation process defined for the external data before it is used to populate the legal document template.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:46 AM
Security Audit — agent-trust-hub — terms-of-service-generator