model-local-data

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were identified. The skill is authored by a known vendor (Automattic) and uses purpose-built tools for website migration.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes content from local website source files (SKILL.md).
  • Ingestion points: Local source files containing JavaScript data arrays or static HTML cards.
  • Boundary markers: Data is extracted without specific adversarial delimiters.
  • Capability inventory: The skill generates a JSON model and utilizes specific conversion tools (liberate_data_model_scaffold, liberate_convert_local_site).
  • Sanitization: Instructions prioritize verbatim extraction of records and faithful reproduction of markup to ensure conversion fidelity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 03:02 AM
Security Audit — agent-trust-hub — model-local-data