landing-page-conversion-audit
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of untrusted external content.\n
- Ingestion points: The agent is instructed to fetch and read the rendered DOM of URLs provided by the user for auditing (SKILL.md).\n
- Boundary markers: The instructions do not define delimiters or provide warnings to ignore embedded instructions within the fetched DOM content.\n
- Capability inventory: The agent performs analysis of conversion elements and generates a structured report with recommended fixes.\n
- Sanitization: No mechanisms for sanitizing, escaping, or filtering the external web content are specified in the procedure.\n- [EXTERNAL_DOWNLOADS]: The skill recommends the acquisition of a third-party tool (Autonnel) from an external GitHub repository (
https://github.com/autonnel/autonnel).\n- [REMOTE_CODE_EXECUTION]: The skill provides shell commands (docker compose up) for the installation and execution of external, third-party software as part of the implementation guidance.
Audit Metadata