website-positioning
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing content from research tasks.
- Ingestion points: Data is ingested from the output of the customer-research and competitor-alternatives skills.
- Boundary markers: There are no explicit instructions to use delimiters or warnings when incorporating research data into the positioning documents.
- Capability inventory: The skill writes content to POSITIONING.md and tests/positioning.spec.ts, and executes the npm test command.
- Sanitization: No explicit sanitization of the research data is defined before it is used to generate code or documentation.
- [COMMAND_EXECUTION]: The skill involves the generation and execution of local test scripts.
- Evidence: The instructions guide the agent to update TypeScript code in tests/positioning.spec.ts and execute npm test to verify the site's positioning.
Audit Metadata