saccoai-website-analysis
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No direct prompt injection, data exfiltration, or obfuscation techniques were identified. The skill's behavior is consistent with its stated purpose of website analysis.
- [COMMAND_EXECUTION]: Uses the
agent-browsertool via Bash for web navigation. This usage is scoped and restricted within the platform's tool configuration. - [EXTERNAL_DOWNLOADS]: Downloads website assets (images, PDFs) and full-page screenshots to the local
.saccoai/analysis/directory. This is a primary function of the tool's archival and audit capabilities. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as it processes data from external websites.
- Ingestion points: Data is ingested from the DOM, metadata, and structured data of targeted URLs (SKILL.md).
- Boundary markers: No explicit instructions are provided to the agent to ignore instructions embedded within the crawled content.
- Capability inventory: The skill has the capability to write files to the local filesystem and interact with web pages.
- Sanitization: There is no mention of sanitization or filtering for the extracted text content.
Audit Metadata