lp-content

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted external data.
  • Ingestion points: The skill ingests user-provided text for 'Business description', 'Target audience', and 'Available proof'. It also optionally reads a user-specified 'Landing page file'.
  • Boundary markers: There are no defined boundary markers (e.g., XML tags or delimiters) or instructions for the agent to ignore commands embedded within the provided content assets or landing page files.
  • Capability inventory: The skill has access to powerful tools including 'bash', 'read', 'write', 'edit', 'glob', and 'grep'.
  • Sanitization: The skill lacks any mechanism to sanitize or validate the content of the ingested files or text before the agent processes them, which could lead to the agent following instructions hidden in the data.
  • [COMMAND_EXECUTION]: The skill's configuration includes the 'bash' tool in the 'allowed-tools' section. However, the instructional logic within the SKILL.md file exclusively focuses on text generation and file manipulation ('write', 'edit') and does not utilize shell commands. This constitutes a violation of the principle of least privilege, as the skill possesses executable capabilities that are unnecessary for its primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 10:10 PM
Security Audit — agent-trust-hub — lp-content