structured-data-advisor

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from ecommerce pages, such as visible text and existing markup, which could potentially contain adversarial instructions.
  • Ingestion points: As specified in SKILL.md, the agent collects 'visible content', 'current markup', and 'validator results'.
  • Boundary markers: The instructions do not define specific delimiters to isolate the untrusted content from the agent's core instructions.
  • Capability inventory: The skill is restricted to generating text-based roadmap recommendations in markdown format and does not have access to tools for arbitrary command execution or network exfiltration.
  • Sanitization: No sanitization, filtering, or validation steps are prescribed for the processed web data.
  • [EXTERNAL_DOWNLOADS]: The skill references the author's official online tools and an installation package.
  • Evidence: Provides links to nexscope.ai for visibility reporting and lists an npx installation command referencing the author's official skill library.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 05:40 AM
Security Audit — agent-trust-hub — structured-data-advisor