website-change-monitor
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The provided files do not include any executable code, scripts, or binary files. The skill relies entirely on high-level metadata and tool definitions.
- [PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection as it fetches content from arbitrary URLs via the webfetch tool and processes it through an agent. Malicious instructions on a monitored website could attempt to influence the agent's behavior.
- Ingestion points: Content retrieved from external URLs (SKILL.md)
- Boundary markers: None specified in the workflow description
- Capability inventory: webfetch for data retrieval and email_send for notification (SKILL.md)
- Sanitization: No sanitization or validation of external content is described
Audit Metadata