website-migration-audit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external URLs provided by the user (production and staging sites) to perform its audit functions.
- Ingestion points: Web content is retrieved using
WebFetchin Steps 2, 3, and 4 to analyze URLs, SEO elements, and page content. - Boundary markers: The instructions lack specific delimiters or instructions to ignore embedded commands, which could allow malicious instructions found on a processed webpage to influence the agent's behavior.
- Capability inventory: The agent is granted access to
WebFetch,Bash,Read, andWritetools, forming a potential exploitation path if the agent is compromised via data ingestion. - Sanitization: There is no evidence of content sanitization or validation performed on the external data before it is analyzed by the agent.
Audit Metadata