Security Audit
anysiteio/agent-skills:skills/anysite-influencer-discovery
github.com/anysiteio/agent-skillsTrust Assessment
anysiteio/agent-skills:skills/anysite-influencer-discovery received a trust score of 96/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Indirect Prompt Injection via Untrusted Web Content.
The analysis covered 4 layers: dependency_graph, llm_behavioral_safety, manifest_analysis, static_code_analysis. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 8, 2026 (commit 34bedfab). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Indirect Prompt Injection via Untrusted Web Content The skill workflow explicitly instructs the agent to visit and parse external websites found in user bios using `parse_webpage`. This creates a vector for indirect prompt injection where malicious content hosted on a target's website could hijack the agent's context or exfiltrate data. Ensure the `parse_webpage` tool runs in a sandboxed environment or that the agent is explicitly instructed to treat the output as untrusted data. Avoid automatic parsing of arbitrary URLs without user confirmation. | Unknown | SKILL.md:268 |
Scan History
Embed Code
[](https://skillshield.io/report/4b8ab7865b15e711)
Powered by SkillShield