effective-web
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill consists entirely of markdown documentation, configuration files, and evaluation datasets. No executable scripts or binary files are present in the provided contents.
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions for the agent to analyze external web resources, screenshots, and videos (e.g., in 'references/route-reference-analysis.md'). This creates a surface for indirect prompt injection where malicious instructions embedded in a target website could influence the agent. The skill provides extensive checklists and audit rubrics that guide the agent to perform objective analysis. Ingestion points: external websites, prototypes, and media recordings in route-reference-analysis.md. Boundary markers: structured observation ledgers and evidence capture protocols. Capability inventory: designing code, authentication flows, and legal compliance surfaces. Sanitization: classification of inputs into an observation ledger rather than direct execution.
- [EXTERNAL_DOWNLOADS]: The README provides installation commands using 'npx' and 'dalo' that point to the author's official domain and GitHub repository ('sebastian-software.com'). These are documented as standard deployment procedures and originate from the skill's verified author.
Audit Metadata