opencli-sitemap-author

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash(opencli:*) tool to execute commands like opencli browser state, find, network, and analyze for site exploration and data verification.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external websites via opencli browser as part of its sitemap authoring workflow.\n
  • Ingestion points: Website content and browser metadata retrieved using opencli browser (SKILL.md).\n
  • Boundary markers: The skill includes 'Red Lines' and validation schema rules (references/sitemap-schema.md) to prevent the inclusion of unsafe data, though it does not specify explicit delimiters for all external content.\n
  • Capability inventory: The skill has access to Bash, Read, Edit, Write, and Grep tools.\n
  • Sanitization: Instructions require capturing only semantic structures and explicitly forbid recording secrets, authentication strategies, or security bypass techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:42 PM
Security Audit — agent-trust-hub — opencli-sitemap-author