linktree-hello-world

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Linktree's documentation and status pages, as well as local repository files, creating a surface for indirect prompt injection.
  • Ingestion points: The skill uses WebFetch to ingest content from help.linktr.ee and status.linktr.ee. It also uses Read, Glob, and Grep to inspect local files such as references/official-docs.md and campaign specifications.
  • Boundary markers: The instructions include clear boundaries, requiring the agent to "separate observed facts from assumptions" and use "redacted receipts."
  • Capability inventory: The skill utilizes Write and Edit tools for recording results and WebFetch for network operations.
  • Sanitization: The instructions explicitly forbid searching credential files and mandate the redaction of sensitive information from receipts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:51 AM
Security Audit — agent-trust-hub — linktree-hello-world