website-migration-audit
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security threats or malicious patterns were detected. The skill's operations, including fetching website content and querying search data, are strictly aligned with its primary purpose of performing a technical SEO audit.
- [PROMPT_INJECTION]: The skill processes untrusted content from external websites via the
WebFetchtool to perform audit comparisons, which constitutes an indirect prompt injection surface (Category 8). - Ingestion points: Untrusted content is retrieved from production and staging URLs provided as arguments (SKILL.md).
- Boundary markers: None identified; untrusted data is processed directly within the agent context.
- Capability inventory: Access to
Bash,Write, and BigQuery execution tools (mcp__cogny__execute_bigquery_sql) (SKILL.md). - Sanitization: No explicit sanitization or validation of the fetched website content is defined in the instructions.
Audit Metadata