geo
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its data processing pipeline.
- Ingestion points:
scripts/crawl.pyfetches untrusted external web content and stores it inevidence/pages.jsonlfor subsequent analysis. - Boundary markers: Untrusted web content is interpolated into LLM prompts in
scripts/bootstrap.py(for brand fact extraction) andscripts/sample.py(for AI answer sampling) without explicit delimiters or instructions to ignore embedded directives. - Capability inventory: The skill possesses significant capabilities including local command execution (
scripts/jobs.py), external network publishing to GitHub, WordPress, and WeChat (scripts/publish.py), and file system write operations. - Sanitization: Content is stripped of HTML boilerplate but is not sanitized or filtered for potential prompt injection markers before being passed to LLM providers.
- [COMMAND_EXECUTION]: The skill executes local shell commands through a dashboard-driven job system.
- The
scripts/jobs.pymodule usessubprocess.Popento run background tasks. Security is maintained by using a list-based argument format and limiting execution to a strict whitelist of subcommands and parameters defined in theACTIONSdictionary. - User-provided project identifiers (slugs) are validated against a strict alphanumeric regex in
scripts/geolib.pybefore being used in file paths or command lines. - [DATA_EXFILTRATION]: The skill transmits project data and credentials to external services as part of its core functionality.
- Brand facts and diagnostic questions are sent to LLM providers including 302.AI, OpenRouter, and native endpoints (OpenAI, Anthropic, etc.).
- The publication system in
scripts/publish.pytransmits generated content to external platforms using credentials managed via the environment. Access to these operations is gated by a local-only dashboard (127.0.0.1) and manual user triggers. - [EXTERNAL_DOWNLOADS]: The skill performs automated web crawling of user-specified target domains.
scripts/crawl.pyimplements a crawler that fetches HTML content. It includes safety guards such as a 4MB per-page download limit and a file extension blacklist to prevent the ingestion of malicious binaries or excessively large files.
Audit Metadata