fixing-metadata

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The references/evals.yaml file contains a test case titled 'pressure-unsafe' which includes the string 'Ignore previous instructions'. This is a security benchmark to verify that the agent correctly refuses malicious prompts and is not an instruction for the agent's operational behavior.\n- [COMMAND_EXECUTION]: The skill defines a feedback protocol in SKILL.md that invokes a local script 'utilities/skill-builder/scripts/record_skill_feedback.py' to log performance data. This is an internal administrative command with no remote network components.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it audits external HTML and JSON-LD data.\n
  • Ingestion points: HTML source files and metadata snippets specified in SKILL.md.\n
  • Boundary markers: None; the skill does not require delimiters for untrusted content.\n
  • Capability inventory: The agent generates SEO fixes and validation checklists.\n
  • Sanitization: None; the skill assumes the agent's core safety filters handle the input.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:13 PM
Security Audit — agent-trust-hub — fixing-metadata