landing-page

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requests and processes user-provided inputs such as audience descriptions, objections, and testimonials to generate landing page content, which represents an attack surface for indirect instructions.\n
  • Ingestion points: Audience context and proof assets defined in SKILL.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore instructions embedded in user data.\n
  • Capability inventory: Skill functionality is restricted to text and outline generation; no high-privilege tools or system access are requested.\n
  • Sanitization: No input validation or sanitization routines are provided.\n- [EXTERNAL_DOWNLOADS]: REFERENCES.md contains a link to a raw markdown file on GitHub from an external user account and a link to official Google developer documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:55 PM
Security Audit — agent-trust-hub — landing-page