landing-page-conversion-audit

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of untrusted external content.\n
  • Ingestion points: The agent is instructed to fetch and read the rendered DOM of URLs provided by the user for auditing (SKILL.md).\n
  • Boundary markers: The instructions do not define delimiters or provide warnings to ignore embedded instructions within the fetched DOM content.\n
  • Capability inventory: The agent performs analysis of conversion elements and generates a structured report with recommended fixes.\n
  • Sanitization: No mechanisms for sanitizing, escaping, or filtering the external web content are specified in the procedure.\n- [EXTERNAL_DOWNLOADS]: The skill recommends the acquisition of a third-party tool (Autonnel) from an external GitHub repository (https://github.com/autonnel/autonnel).\n- [REMOTE_CODE_EXECUTION]: The skill provides shell commands (docker compose up) for the installation and execution of external, third-party software as part of the implementation guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — landing-page-conversion-audit