geo-crawlers

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes untrusted data from external websites (robots.txt, HTML meta tags, and HTTP headers) using the WebFetch tool. An attacker who controls a site being analyzed could embed malicious instructions in these fields to attempt to influence the agent's behavior.
  • Ingestion points: External URLs provided by users to be processed by the instructions in SKILL.md (Analysis Procedure).
  • Boundary markers: The instructions lack explicit warnings to treat fetched content strictly as data or delimiters to separate data from instructions during parsing.
  • Capability inventory: The skill has access to Bash, Write, Read, Grep, Glob, and WebFetch tools as defined in the SKILL.md frontmatter, which could be abused if an injection is successful.
  • Sanitization: No sanitization or validation of the fetched content is described in SKILL.md before parsing and inclusion in the final report.
  • [COMMAND_EXECUTION]: The skill includes Bash in its allowed-tools list. While the instructions primarily focus on parsing data, the availability of a shell environment alongside tools that fetch external data increases the potential impact of an instruction injection from an untrusted web source.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 10:59 AM
Security Audit — agent-trust-hub — geo-crawlers