meta-in-body

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves a legitimate SEO auditing purpose and does not exhibit malicious behavior. Findings are consistent with standard web development diagnostic workflows.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it fetches and processes external HTML content. However, this is a core requirement for its primary auditing purpose. Evidence chain: Ingestion occurs via the curl command in references/rule.md; no specific boundary markers are defined to isolate untrusted HTML; capabilities include network fetching and string parsing; no explicit sanitization is performed on the input.
  • [EXTERNAL_DOWNLOADS]: The skill references well-known and reputable technical documentation sources, including Mozilla Developer Network (MDN) and the World Wide Web Consortium (W3C). These resources are used for standard reference and do not involve the execution of untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 05:58 PM
Security Audit — agent-trust-hub — meta-in-body