astro-content
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from external Markdown/MDX files and remote APIs through the content layer.
- Ingestion points: Data enters the agent context through file-based collections in
./src/docsor./src/contentand remote data fetched via custom loaders (defined inSKILL.mdandreferences/content-layer.md). - Boundary markers: The skill advocates for mandatory Zod schemas (
references/schema.md) which provide build-time validation for frontmatter, though they do not prevent injection within the content body itself. - Capability inventory: The system allows for rendering Markdown, executing components within MDX files, and executing arbitrary code within custom loaders (
references/markdown-mdx.md). - Sanitization: The documentation explicitly warns against rendering untrusted MDX and suggests using
rehype-sanitizefor raw HTML content (references/markdown-mdx.md). - [REMOTE_CODE_EXECUTION]: The skill supports the use of custom loaders and MDX components which can execute code at build or request time.
- Evidence: Documentation in
references/content-layer.mddescribes custom loaders as functions that can fetch remote data, andreferences/markdown-mdx.mdhighlights that MDX executes imported components. The skill mitigates this by providing developer warnings to treat MDX as code and avoid processing untrusted sources.
Audit Metadata