fixing-metadata

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and modify HTML metadata which may be derived from external or untrusted sources.
  • Ingestion points: The agent reads existing HTML files, metadata tags, and JSON-LD structured data blocks from the project context.
  • Boundary markers: The instructions do not define specific delimiters for separating the metadata content being audited from the agent's instructions.
  • Capability inventory: The skill is authorized to perform file-system write operations to fix metadata issues in HTML and component files.
  • Sanitization: The skill proactively mitigates this risk by including a critical rule to "escape and sanitize any user-generated or dynamic strings" during the audit and fix process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:06 PM
Security Audit — agent-trust-hub — fixing-metadata