website-positioning

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing content from research tasks.
  • Ingestion points: Data is ingested from the output of the customer-research and competitor-alternatives skills.
  • Boundary markers: There are no explicit instructions to use delimiters or warnings when incorporating research data into the positioning documents.
  • Capability inventory: The skill writes content to POSITIONING.md and tests/positioning.spec.ts, and executes the npm test command.
  • Sanitization: No explicit sanitization of the research data is defined before it is used to generate code or documentation.
  • [COMMAND_EXECUTION]: The skill involves the generation and execution of local test scripts.
  • Evidence: The instructions guide the agent to update TypeScript code in tests/positioning.spec.ts and execute npm test to verify the site's positioning.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 04:43 PM
Security Audit — agent-trust-hub — website-positioning