quilium-webmaster
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is instructed to fetch its core operating procedures at runtime from a remote 'Quilium MCP skill library' using the
get-skilltool. This makes the agent's behavior dependent on content retrieved from an external server managed by the vendor. - [INDIRECT_PROMPT_INJECTION]: The instructions mandate loading and prioritizing 'site procedures' (prefixed with
site:) which are written by users or site administrators within the CMS settings. The skill is explicitly told to follow these site-specific instructions 'over the generic skills wherever the two disagree,' creating a potential vector for indirect prompt injection if the CMS content is compromised or maliciously authored. - [DATA_EXPOSURE]: The skill has broad access to site content, navigation, and SEO metadata through tools like
get-site-settings,get-navigations-with-pages, andget-ai-skills. While these are intended for CMS management, they involve the processing of sensitive site configuration data.
Audit Metadata