pricing-page

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided data regarding product offers, pricing plans, and audience details to generate structured page outlines. This interaction model represents a potential surface for indirect prompt injection if the input contains adversarial instructions. However, the risk is inherent to the skill's primary function of content generation.
  • Ingestion points: SKILL.md instructions for gathering "Offer + audience", "Plans", and "Objections" data.
  • Boundary markers: None present to delimit user input from agent instructions.
  • Capability inventory: No file-system writes, network operations, or command executions are present in the skill scripts.
  • Sanitization: No specific instructions for sanitizing or escaping user-provided content.
  • [EXTERNAL_DOWNLOADS]: The skill references external URLs in REFERENCES.md for informational purposes, including official documentation from Google and an example marketing repository on GitHub. These are static references intended for human reading and do not trigger automated script execution or package downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — pricing-page