cro

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze marketing pages from user-provided external URLs. This creates an attack surface where a maliciously crafted webpage could contain instructions designed to override the agent's behavior during the analysis.
  • Ingestion points: External URLs for homepages, landing pages, and pricing pages provided by the user for analysis.
  • Boundary markers: The instructions do not specify the use of delimiters or explicit warnings to the agent to ignore instructions embedded within the target page content.
  • Capability inventory: The agent is expected to use its built-in browser or web-search tools to retrieve the page content for review.
  • Sanitization: No sanitization or validation logic is defined to filter the content of the analyzed pages before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:35 AM
Security Audit — agent-trust-hub — cro