paid-landing-page-audit

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process third-party landing page content, which represents an indirect prompt injection surface.
  • Ingestion points: The audit workflow involves processing user-supplied live URLs, pasted HTML, or text descriptions of landing pages (SKILL.md).
  • Boundary markers: The instructions include a dedicated 'Untrusted Page Content' section that explicitly mandates ignoring any directives found within page markup, scripts, or redirects.
  • Capability inventory: The skill does not request or utilize tools for file system modification, shell command execution, or network exfiltration, which significantly limits the potential impact of any injection.
  • Sanitization: Relies on strong instructional constraints to distinguish between audited data and operational commands.
  • [SAFE]: A thorough review of the skill instructions, metadata, and reference files found no evidence of prompt injection, obfuscated content, or unauthorized external code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:32 PM
Security Audit — agent-trust-hub — paid-landing-page-audit