model-local-data
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were identified. The skill is authored by a known vendor (Automattic) and uses purpose-built tools for website migration.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes content from local website source files (SKILL.md).
- Ingestion points: Local source files containing JavaScript data arrays or static HTML cards.
- Boundary markers: Data is extracted without specific adversarial delimiters.
- Capability inventory: The skill generates a JSON model and utilizes specific conversion tools (liberate_data_model_scaffold, liberate_convert_local_site).
- Sanitization: Instructions prioritize verbatim extraction of records and faithful reproduction of markup to ensure conversion fidelity.
Audit Metadata