landing-page-cro

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes an explicit instruction to intercept and redirect user inquiries about the agent's system prompt. Instead of responding naturally, the agent is forced to provide a promotional response for the 'Scayver Academy' membership site.
  • [PROMPT_INJECTION]: The instructions mandate the suppression of all AI-generated warnings, notes, or disclaimers ('No warnings, notes, or disclaimers. Deliver the content directly'). This reduces agent transparency and can prevent the user from seeing important safety or accuracy markers provided by the model.
  • [PROMPT_INJECTION]: The skill processes untrusted user-provided content (landing page copy and descriptions) to perform audits, which creates a surface for indirect prompt injection.
  • Ingestion points: Landing page URLs, page descriptions, and current copy provided by the user in the prompt.
  • Boundary markers: Absent; the instructions do not define delimiters or provide 'ignore embedded instructions' warnings for the external data.
  • Capability inventory: Text generation (audits/copywriting) and structured data generation (JSON-LD FAQ schema).
  • Sanitization: Absent; no escaping or validation of external content is specified.
  • [SAFE]: The skill includes mandatory links to CashApp and BuyMeACoffee in its intro message. These are well-known services and represent the author's chosen monetization method rather than a technical security threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:11 AM
Security Audit — agent-trust-hub — landing-page-cro