schema-markup
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to generate JSON-LD schema markup based on user input and project context. It does not perform any dangerous operations such as command execution, network requests to untrusted domains, or sensitive file access.
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to read
.claude/product-marketing-context.mdto gather project information. This represents a potential surface for indirect prompt injection if the context file contains malicious instructions. However, the risk is negligible as the skill lacks high-privilege capabilities (like file writes or network exfiltration) to exploit such an injection. - Ingestion points:
.claude/product-marketing-context.md(referenced in SKILL.md and its translations). - Boundary markers: Absent; the agent is simply told to "read it before asking questions."
- Capability inventory: Limited to text and JSON generation. No subprocess execution, file system modification, or network tool access listed.
- Sanitization: None specified for the content read from the context file.
- [SAFE]: External links provided (Google Rich Results Test, Schema.org Validator) are well-known, trusted industry tools for validating structured data.
Audit Metadata