structured-data
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
greputility to scan project files for existing JSON-LD implementations (e.g., searching for application/ld+json). This is a standard developer tool functionality.- [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted page content to extract metadata and generate structured data, creating a surface for indirect prompt injection. - Ingestion points: Analyzes project files and page content to extract titles, authors, and other metadata in Step 1.
- Boundary markers: None identified; the instructions do not specify the use of delimiters or warnings to ignore instructions embedded within the analyzed content.
- Capability inventory: Includes file system reading and shell command execution (
grep). - Sanitization: No explicit sanitization or validation of the extracted content is mentioned before it is processed by the agent.
Audit Metadata