local-sponsorship-link-building
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to browse and analyze content from external websites (sponsor pages, community organizations) during the prospecting and evaluation phases. This creates a surface for indirect prompt injection if an attacker-controlled page contains malicious instructions designed to influence the agent's behavior.
- Ingestion points:
workflows/plan-local-sponsorship-campaign.md(Steps 2 & 3). - Boundary markers: Not present; the instructions do not include specific delimiters or warnings to ignore instructions found on external sites.
- Capability inventory: The skill itself contains no scripts or tools and does not request any specific capabilities in the frontmatter. Behavior depends on the agent's default toolset.
- Sanitization: Not present; content is processed directly for the evaluation rubric.
- [NO_CODE]: The skill is composed exclusively of Markdown documentation and workflows. There are no Python scripts, JavaScript files, or shell commands that could execute malicious logic on the host system.
Audit Metadata