korean-product-detail-page

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes content from user-provided URLs to gather research data, creating a surface for indirect prompt injection.
  • Ingestion points: Instructions in references/browser-link-research.ko.md and rules/korean-product-detail-page-workflow.md direct the agent to analyze rendered content from external links.
  • Boundary markers: The workflow lacks explicit delimiters or instructions to treat remote content as untrusted data.
  • Capability inventory: The agent has permissions to write to the local file system (.hypercore/), utilize browser automation via Chrome DevTools Protocol (CDP), and invoke the skills/image-generation tool.
  • Sanitization: There are no defined procedures for sanitizing or filtering instructions that might be embedded in the HTML or visible text of researched pages.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 05:51 AM