landing-page
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requests and processes user-provided inputs such as audience descriptions, objections, and testimonials to generate landing page content, which represents an attack surface for indirect instructions.\n
- Ingestion points: Audience context and proof assets defined in SKILL.md.\n
- Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore instructions embedded in user data.\n
- Capability inventory: Skill functionality is restricted to text and outline generation; no high-privilege tools or system access are requested.\n
- Sanitization: No input validation or sanitization routines are provided.\n- [EXTERNAL_DOWNLOADS]: REFERENCES.md contains a link to a raw markdown file on GitHub from an external user account and a link to official Google developer documentation.
Audit Metadata