author-byline
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze untrusted external data, which creates a potential surface for indirect prompt injection attacks.
- Ingestion points: The instructions in
SKILL.mddirect the agent to "Verify the rendered HTML and HTTP response" and "Review metadata generation, rendered HTML, structured data, and response headers." - Boundary markers: No specific boundary markers or instructions to ignore embedded commands within the analyzed content are provided.
- Capability inventory: The skill leverages the agent's inherent capabilities to fetch web content and interpret structured data and headers.
- Sanitization: There are no specified sanitization or validation steps for the external data being processed.
Audit Metadata