saccoai-website-analysis

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No direct prompt injection, data exfiltration, or obfuscation techniques were identified. The skill's behavior is consistent with its stated purpose of website analysis.
  • [COMMAND_EXECUTION]: Uses the agent-browser tool via Bash for web navigation. This usage is scoped and restricted within the platform's tool configuration.
  • [EXTERNAL_DOWNLOADS]: Downloads website assets (images, PDFs) and full-page screenshots to the local .saccoai/analysis/ directory. This is a primary function of the tool's archival and audit capabilities.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as it processes data from external websites.
  • Ingestion points: Data is ingested from the DOM, metadata, and structured data of targeted URLs (SKILL.md).
  • Boundary markers: No explicit instructions are provided to the agent to ignore instructions embedded within the crawled content.
  • Capability inventory: The skill has the capability to write files to the local filesystem and interact with web pages.
  • Sanitization: There is no mention of sanitization or filtering for the extracted text content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 07:15 PM