website-migration-audit

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security threats or malicious patterns were detected. The skill's operations, including fetching website content and querying search data, are strictly aligned with its primary purpose of performing a technical SEO audit.
  • [PROMPT_INJECTION]: The skill processes untrusted content from external websites via the WebFetch tool to perform audit comparisons, which constitutes an indirect prompt injection surface (Category 8).
  • Ingestion points: Untrusted content is retrieved from production and staging URLs provided as arguments (SKILL.md).
  • Boundary markers: None identified; untrusted data is processed directly within the agent context.
  • Capability inventory: Access to Bash, Write, and BigQuery execution tools (mcp__cogny__execute_bigquery_sql) (SKILL.md).
  • Sanitization: No explicit sanitization or validation of the fetched website content is defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 06:43 AM
Security Audit — agent-trust-hub — website-migration-audit