landing-page-design
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
belt-sh/clipackage vianpxand refers to external installation documents on GitHub (inference-sh/skills). - [REMOTE_CODE_EXECUTION]: The skill instructs the user to install an external package (
belt-sh/cli) and run remote applications using thebelttool, which involves executing code from third-party sources. - [COMMAND_EXECUTION]: The skill provides instructions to run the
beltCLI tool for logging in and executing various remote applications, which involves running shell commands. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from external search applications like Tavily and Exa.
- Ingestion points: Data retrieved from web searches by
tavily/search-assistantandexa/answer(SKILL.md). - Boundary markers: Absent; there are no specific markers used to delimit untrusted search results from the rest of the prompt context.
- Capability inventory: The skill has the capability to run the
beltCLI tool and install external skills (SKILL.md). - Sanitization: Absent; the skill does not specify any filtering or sanitization steps for the data received from external tools.
Audit Metadata