paywall-teardown
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of screenshots and JSON configurations, creating a surface for indirect prompt injection.
- Ingestion points: Paywall screenshots, renders (PNG), and Flow Builder JSON configurations provided by users in SKILL.md.
- Boundary markers: The instructions include boundary directives to "Reason only from what is in front of you" and to treat the provided patterns.md library as a "moat" to ground recommendations.
- Capability inventory: The skill is limited to generating text-based growth analysis and markdown tables; it lacks capabilities for file system writes, network exfiltration, or shell command execution.
- Sanitization: There is no explicit sanitization or filtering of the processed input content mentioned in the instructions.
Audit Metadata