marketing-landing-page-conversion-audit

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed entirely of natural language instructions and structural templates for conducting marketing audits. It contains no executable scripts or system-level commands.
  • [SAFE]: All referenced skills and tool chains (e.g., moai-marketer, moai-coworker) belong to the author's own ecosystem, representing standard modular functionality.
  • [SAFE]: No instances of prompt injection, code obfuscation, or malicious persistence mechanisms were detected in the instructions or metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data via external landing page URLs and screenshots. This is a known attack surface but is essential to the skill's primary function and is mitigated by the platform's underlying LLM safety guardrails.
  • Ingestion points: Users provide a landing page URL or screenshot in the SKILL.md input slots.
  • Boundary markers: The skill does not explicitly define delimiters for external content but expects a structured JSON output.
  • Capability inventory: The skill itself does not have file-write or network-send capabilities; it relies on the agent's standard toolset for browsing.
  • Sanitization: No explicit sanitization of the landing page content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — marketing-landing-page-conversion-audit