astro-content

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from external Markdown/MDX files and remote APIs through the content layer.
  • Ingestion points: Data enters the agent context through file-based collections in ./src/docs or ./src/content and remote data fetched via custom loaders (defined in SKILL.md and references/content-layer.md).
  • Boundary markers: The skill advocates for mandatory Zod schemas (references/schema.md) which provide build-time validation for frontmatter, though they do not prevent injection within the content body itself.
  • Capability inventory: The system allows for rendering Markdown, executing components within MDX files, and executing arbitrary code within custom loaders (references/markdown-mdx.md).
  • Sanitization: The documentation explicitly warns against rendering untrusted MDX and suggests using rehype-sanitize for raw HTML content (references/markdown-mdx.md).
  • [REMOTE_CODE_EXECUTION]: The skill supports the use of custom loaders and MDX components which can execute code at build or request time.
  • Evidence: Documentation in references/content-layer.md describes custom loaders as functions that can fetch remote data, and references/markdown-mdx.md highlights that MDX executes imported components. The skill mitigates this by providing developer warnings to treat MDX as code and avoid processing untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 04:10 PM
Security Audit — agent-trust-hub — astro-content