fixing-metadata
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and modify HTML metadata which may be derived from external or untrusted sources.
- Ingestion points: The agent reads existing HTML files, metadata tags, and JSON-LD structured data blocks from the project context.
- Boundary markers: The instructions do not define specific delimiters for separating the metadata content being audited from the agent's instructions.
- Capability inventory: The skill is authorized to perform file-system write operations to fix metadata issues in HTML and component files.
- Sanitization: The skill proactively mitigates this risk by including a critical rule to "escape and sanitize any user-generated or dynamic strings" during the audit and fix process.
Audit Metadata