page-cro

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external content from URLs or local files through its audit script, which creates a potential surface for indirect prompt injection. \n
  • Ingestion points: The scripts/conversion_audit.py script fetches and parses data from user-specified URLs or local HTML files. \n
  • Boundary markers: The instructions do not define explicit boundary markers or delimiters to separate the untrusted audited text from the system instructions. \n
  • Capability inventory: The skill is primarily designed for analysis and lacks capabilities to write to the filesystem, execute arbitrary shell commands, or perform unauthorized data exfiltration. \n
  • Sanitization: The script performs basic HTML parsing but does not sanitize the extracted text for linguistic patterns intended to override agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:32 PM
Security Audit — agent-trust-hub — page-cro