AGENT LAB: SKILLS

defuddle

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • EXTERNAL_DOWNLOADS (MEDIUM): The skill instructs the user to install an external dependency 'defuddle-cli' via npm. This package is not from a recognized trusted organization, presenting a potential risk for unverified code execution in the environment.- PROMPT_INJECTION (LOW): The skill facilitates indirect prompt injection by fetching and parsing content from external URLs. Evidence chain: 1. Ingestion point: Web content is ingested via the 'defuddle parse' command. 2. Boundary markers: The skill does not provide delimiters or instructions for the agent to ignore instructions within the fetched data. 3. Capability inventory: Uses subprocess execution to run the 'defuddle' CLI tool. 4. Sanitization: The tool removes HTML structure but does not filter for adversarial natural language instructions in the text.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 04:50 PM