landing-page-design
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
belt-sh/clipackage and references a remote installation guide located athttps://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md. - [COMMAND_EXECUTION]: The skill utilizes the
beltCLI tool to run remote applications for image generation (falai/flux-dev-lora,bytedance/seedream-4-5) and research (tavily/search-assistant,exa/answer). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external search providers, which constitutes a potential attack surface for indirect prompt injection.
- Ingestion points: External research data retrieved via the
tavily/search-assistantandexa/answerapplications inSKILL.md. - Boundary markers: No specific delimiters or safety instructions are provided to the agent to distinguish between its primary instructions and the untrusted data from tool outputs.
- Capability inventory: The skill possesses the capability to execute shell commands using the
belttool, allowing it to act on information gathered from the search tools. - Sanitization: The skill does not specify any sanitization, filtering, or validation steps for the content returned by external research tools.
Audit Metadata