onboard-site
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by processing untrusted external data.\n
- Ingestion points: The skill uses
list_sitemaps_enhancedto read XML data from remote servers and references anseo-auditskill that parses live website content.\n - Boundary markers: No explicit boundaries, delimiters, or instructions are provided to the agent to treat external content as data only or to ignore embedded instructions within that content.\n
- Capability inventory: The agent has the ability to perform network submissions via
submit_sitemapand other onboarding tools, which could be abused if an injection is successful.\n - Sanitization: The instructions do not define any sanitization, validation, or filtering of the content ingested from the target website or sitemap.
Audit Metadata