structured-data

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the grep utility to scan project files for existing JSON-LD implementations (e.g., searching for application/ld+json). This is a standard developer tool functionality.- [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted page content to extract metadata and generate structured data, creating a surface for indirect prompt injection.
  • Ingestion points: Analyzes project files and page content to extract titles, authors, and other metadata in Step 1.
  • Boundary markers: None identified; the instructions do not specify the use of delimiters or warnings to ignore instructions embedded within the analyzed content.
  • Capability inventory: Includes file system reading and shell command execution (grep).
  • Sanitization: No explicit sanitization or validation of the extracted content is mentioned before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 12:19 PM
Security Audit — agent-trust-hub — structured-data