schema

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data to generate JSON-LD schema markup, creating a potential surface for indirect prompt injection.
  • Ingestion points: Untrusted content provided by the user to populate schema fields (e.g., product descriptions, FAQ answers) as defined in the 'Task-Specific Questions' section of SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the user-provided data are defined.
  • Capability inventory: The skill is capable of generating JSON-LD code blocks intended for implementation in website source code.
  • Sanitization: The instructions do not specify sanitization or escaping procedures for external content before it is interpolated into the generated code.
  • [SAFE]: The skill references established tools and documentation from well-known services for validation purposes.
  • Evidence: References the official Google Rich Results Test (search.google.com) and the Schema.org Validator (validator.schema.org) for testing implementations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:16 AM
Security Audit — agent-trust-hub — schema