quilium-webmaster

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is instructed to fetch its core operating procedures at runtime from a remote 'Quilium MCP skill library' using the get-skill tool. This makes the agent's behavior dependent on content retrieved from an external server managed by the vendor.
  • [INDIRECT_PROMPT_INJECTION]: The instructions mandate loading and prioritizing 'site procedures' (prefixed with site:) which are written by users or site administrators within the CMS settings. The skill is explicitly told to follow these site-specific instructions 'over the generic skills wherever the two disagree,' creating a potential vector for indirect prompt injection if the CMS content is compromised or maliciously authored.
  • [DATA_EXPOSURE]: The skill has broad access to site content, navigation, and SEO metadata through tools like get-site-settings, get-navigations-with-pages, and get-ai-skills. While these are intended for CMS management, they involve the processing of sensitive site configuration data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:55 AM
Security Audit — agent-trust-hub — quilium-webmaster