geo

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its data processing pipeline.
  • Ingestion points: scripts/crawl.py fetches untrusted external web content and stores it in evidence/pages.jsonl for subsequent analysis.
  • Boundary markers: Untrusted web content is interpolated into LLM prompts in scripts/bootstrap.py (for brand fact extraction) and scripts/sample.py (for AI answer sampling) without explicit delimiters or instructions to ignore embedded directives.
  • Capability inventory: The skill possesses significant capabilities including local command execution (scripts/jobs.py), external network publishing to GitHub, WordPress, and WeChat (scripts/publish.py), and file system write operations.
  • Sanitization: Content is stripped of HTML boilerplate but is not sanitized or filtered for potential prompt injection markers before being passed to LLM providers.
  • [COMMAND_EXECUTION]: The skill executes local shell commands through a dashboard-driven job system.
  • The scripts/jobs.py module uses subprocess.Popen to run background tasks. Security is maintained by using a list-based argument format and limiting execution to a strict whitelist of subcommands and parameters defined in the ACTIONS dictionary.
  • User-provided project identifiers (slugs) are validated against a strict alphanumeric regex in scripts/geolib.py before being used in file paths or command lines.
  • [DATA_EXFILTRATION]: The skill transmits project data and credentials to external services as part of its core functionality.
  • Brand facts and diagnostic questions are sent to LLM providers including 302.AI, OpenRouter, and native endpoints (OpenAI, Anthropic, etc.).
  • The publication system in scripts/publish.py transmits generated content to external platforms using credentials managed via the environment. Access to these operations is gated by a local-only dashboard (127.0.0.1) and manual user triggers.
  • [EXTERNAL_DOWNLOADS]: The skill performs automated web crawling of user-specified target domains.
  • scripts/crawl.py implements a crawler that fetches HTML content. It includes safety guards such as a 4MB per-page download limit and a file extension blacklist to prevent the ingestion of malicious binaries or excessively large files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 04:58 PM