ghl-page
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to read sensitive environment files at
~/.claude/ad-profiles/.envto retrieve the GoHighLevel Private Integration Token. Accessing files containing credentials introduces a risk of sensitive data exposure within the agent's context. - [REMOTE_CODE_EXECUTION]: The skill recommends the execution of external code via the command
npx impeccable install. This involves downloading and running a package from a public registry that is not associated with a trusted organization or well-known service. - [EXTERNAL_DOWNLOADS]: The skill refers to an optional plugin
frontend-design@claude-plugins-officialfrom a trusted organization for design assistance. - [INDIRECT_PROMPT_INJECTION]: The skill processes brand profile markdown files without delimiters or sanitization, creating a surface for indirect prompt injection. Ingestion points: Brand profile markdown files. Boundary markers: None. Capability inventory: Generates HTML/JS code and reads filesystem. Sanitization: None.
- [DYNAMIC_EXECUTION]: The generated landing page code uses JavaScript to dynamically inject CSS styles at runtime to bypass platform limitations that strip static style tags.
Audit Metadata