Reversal — Agent Input Reliability Layer

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The `SKILL.md` file defines tools that allow an agent to read arbitrary URLs and local files via absolute paths (`upload_file`), which are then processed or transmitted to an external endpoint (`api.reversal.dev`). While the documentation describes security mitigations like SSRF protection and extension allowlisting, the inherent capability to access sensitive local data and send it to a third-party service poses a significant risk of data exfiltration if the agent is misdirected. No evidence of intentional malice, such as obfuscation or hidden prompt injections, was found in the provided files.