migration
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests external data from sitemaps and online research, creating a potential surface for indirect prompt injection attacks.
- Ingestion points:
sitemap.xmlfiles used for route discovery and external synthesis provided by theagent:researchskill. - Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore embedded instructions' prompts when processing sitemap URLs or research data.
- Capability inventory: The skill uses shell commands (
git,pnpm), browser automation via Playwright, and file modification capabilities. - Sanitization: Absent; there is no mention of sanitizing or validating the content of the sitemap or the research results before use.
- [COMMAND_EXECUTION]: The skill uses standard development tools including
gitandpnpm. These are used for version control (stash/pop) and dependency management (pnpm install), which are necessary and expected for a migration-focused skill.
Audit Metadata