marketing-landing-page-conversion-audit
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of natural language instructions and structural templates for conducting marketing audits. It contains no executable scripts or system-level commands.
- [SAFE]: All referenced skills and tool chains (e.g.,
moai-marketer,moai-coworker) belong to the author's own ecosystem, representing standard modular functionality. - [SAFE]: No instances of prompt injection, code obfuscation, or malicious persistence mechanisms were detected in the instructions or metadata.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data via external landing page URLs and screenshots. This is a known attack surface but is essential to the skill's primary function and is mitigated by the platform's underlying LLM safety guardrails.
- Ingestion points: Users provide a landing page URL or screenshot in the
SKILL.mdinput slots. - Boundary markers: The skill does not explicitly define delimiters for external content but expects a structured JSON output.
- Capability inventory: The skill itself does not have file-write or network-send capabilities; it relies on the agent's standard toolset for browsing.
- Sanitization: No explicit sanitization of the landing page content is defined.
Audit Metadata