paid-landing-page-audit
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process third-party landing page content, which represents an indirect prompt injection surface.
- Ingestion points: The audit workflow involves processing user-supplied live URLs, pasted HTML, or text descriptions of landing pages (SKILL.md).
- Boundary markers: The instructions include a dedicated 'Untrusted Page Content' section that explicitly mandates ignoring any directives found within page markup, scripts, or redirects.
- Capability inventory: The skill does not request or utilize tools for file system modification, shell command execution, or network exfiltration, which significantly limits the potential impact of any injection.
- Sanitization: Relies on strong instructional constraints to distinguish between audited data and operational commands.
- [SAFE]: A thorough review of the skill instructions, metadata, and reference files found no evidence of prompt injection, obfuscated content, or unauthorized external code execution.
Audit Metadata