fixing-metadata
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The references/evals.yaml file contains a test case titled 'pressure-unsafe' which includes the string 'Ignore previous instructions'. This is a security benchmark to verify that the agent correctly refuses malicious prompts and is not an instruction for the agent's operational behavior.\n- [COMMAND_EXECUTION]: The skill defines a feedback protocol in SKILL.md that invokes a local script 'utilities/skill-builder/scripts/record_skill_feedback.py' to log performance data. This is an internal administrative command with no remote network components.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it audits external HTML and JSON-LD data.\n
- Ingestion points: HTML source files and metadata snippets specified in SKILL.md.\n
- Boundary markers: None; the skill does not require delimiters for untrusted content.\n
- Capability inventory: The agent generates SEO fixes and validation checklists.\n
- Sanitization: None; the skill assumes the agent's core safety filters handle the input.
Audit Metadata