directory-submissions

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional content and reference data for marketing purposes. No malicious code, obfuscation, or unauthorized data access patterns were identified across the provided files.
  • [COMMAND_EXECUTION]: The instructions recommend using the 'curl' utility to verify that directory listings have correctly implemented 'dofollow' links. This is a standard technical verification step for SEO tasks.
  • [DATA_EXFILTRATION]: The skill reads project-specific metadata from local files such as '.agents/product-marketing-context.md'. While it interacts with external URLs for listing verification, it does not attempt to exfiltrate this local data.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from user-managed context files and external directory pages, creating a surface for indirect prompt injection. 1. Ingestion points: '.agents/product-marketing-context.md' and '.claude/product-marketing-context.md'. 2. Boundary markers: Absent. 3. Capability inventory: Network access and shell command execution via 'curl'. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 10:15 PM
Security Audit — agent-trust-hub — directory-submissions