nfadp
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE]: The skill documentation in 'Paso 6' references a hardcoded local file path:
C:/Users/cmano/claude-seo/[cliente]/auditoria_nfadp_[fecha].md. This pattern exposes a specific local directory structure and a username ('cmano') associated with the author's development environment. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to audit external websites, creating a surface for processing untrusted content.
- Ingestion points: External website content is fetched as the primary data source in 'Paso 1'.
- Boundary markers: The instructions do not define clear delimiters or specific instructions for the agent to disregard potential commands embedded in the audited website's text.
- Capability inventory: The skill requires file-writing capabilities to generate the audit report (Paso 6).
- Sanitization: There are no explicit instructions for sanitizing or escaping the data retrieved from the target URL before it is processed by the agent.
Audit Metadata