sitelinks

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes content from several local files to generate its output, creating a potential surface for indirect prompt injection if the source files contain untrusted data.
  • Ingestion points: Data is loaded from .claude/skills/landing-pages/SKILL.md, .claude/skills/brand-voice/SKILL.md, and .claude/skills/icp/SKILL.md.
  • Boundary markers: The instructions do not include specific delimiters or warnings to ignore instructions that might be embedded within the context files.
  • Capability inventory: The skill has access to Read, Write, and Bash tools, which can be used to modify the filesystem or execute commands based on interpreted data.
  • Sanitization: There is no explicit requirement for the agent to sanitize or validate the content retrieved from external skill files before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 08:28 AM
Security Audit — agent-trust-hub — sitelinks