dineway-content-monitor

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret data from external, untrusted sources such as AI engine responses (ChatGPT, Perplexity, Gemini, etc.), Google Search Console data, and direct web crawls. This creates a vulnerability where adversarial content within these external sources could attempt to influence the agent's monitoring logic or automated fix-triggering workflow.
  • Ingestion points: Content is retrieved through Browser Use, local engine clients, and search console connectors as described in SKILL.md and references/ai-visibility.md.
  • Boundary markers: The instructions lack specific boundary markers or explicit prompts to ignore instructions embedded in the retrieved content.
  • Capability inventory: The skill utilizes tools to evaluate observations and generate fix triggers (content_pipeline_monitor_observation_evaluate, content_pipeline_fix_trigger_get) and writes evidence to local JSON files.
  • Sanitization: There is no evidence of sanitization or validation of the external content before it is processed for diagnosis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 02:28 AM
Security Audit — agent-trust-hub — dineway-content-monitor