geo-llmstxt

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from external websites.
  • Ingestion points: The agent is directed to crawl and extract information from arbitrary external domains, including llms.txt files, XML sitemaps, and HTML content (titles, meta descriptions, and page text).
  • Boundary markers: The instructions do not define boundary delimiters or provide instructions to the agent to disregard potential commands embedded within the fetched external content.
  • Capability inventory: The execution environment for this skill includes access to potentially sensitive tools such as Bash, WebFetch, and Write.
  • Sanitization: There are no explicit requirements or steps within the skill to sanitize, escape, or validate content retrieved from external sources before it is used to generate analysis reports or local files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:25 AM
Security Audit — agent-trust-hub — geo-llmstxt