knoxhub-blog
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior or patterns were detected. The skill is well-documented and its instructions align with its stated purpose of generating SEO-optimized content.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from user-provided URLs, creating a surface for indirect prompt injection. However, this risk is inherent to the skill's primary function of content research and rewriting.\n
- Ingestion points: The agent is instructed to fetch content from user-provided URLs using the
WebFetchtool inSKILL.md.\n - Boundary markers: The instructions lack explicit delimiters or warnings to treat the fetched content strictly as data, though the rigid output schema for SEO fields acts as a natural constraint.\n
- Capability inventory: The agent is granted access to powerful tools including
Bash,Write, andWebFetch.\n - Sanitization: No specific sanitization or validation of external content is performed before processing.
Audit Metadata