korean-product-detail-page
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes content from user-provided URLs to gather research data, creating a surface for indirect prompt injection.
- Ingestion points: Instructions in references/browser-link-research.ko.md and rules/korean-product-detail-page-workflow.md direct the agent to analyze rendered content from external links.
- Boundary markers: The workflow lacks explicit delimiters or instructions to treat remote content as untrusted data.
- Capability inventory: The agent has permissions to write to the local file system (.hypercore/), utilize browser automation via Chrome DevTools Protocol (CDP), and invoke the skills/image-generation tool.
- Sanitization: There are no defined procedures for sanitizing or filtering instructions that might be embedded in the HTML or visible text of researched pages.
Audit Metadata