page-cro

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze external, untrusted marketing page content, creating a potential vector for indirect prompt injection.\n
  • Ingestion points: The skill explicitly requests context from marketing pages, including copy and layout elements from homepages, landing pages, and pricing pages (SKILL.md, Initial Assessment section).\n
  • Boundary markers: Absent. The instructions do not provide the agent with specific delimiters or guidance to ignore instructions that might be embedded within the external page content being analyzed.\n
  • Capability inventory: While the skill body is purely instructional, it is intended for use in tool-augmented environments (such as those mentioned in skill-report.json) where file access or browsing may be available.\n
  • Sanitization: Absent. There is no instruction for the agent to filter or sanitize the content of the analyzed pages before processing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 08:19 PM
Security Audit — agent-trust-hub — page-cro