sitemap-4xx
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external XML sitemaps and the URLs contained within them, which presents a surface for indirect prompt injection where malicious instructions could be embedded in the external data.\n
- Ingestion points: XML sitemaps and content from extracted URLs (SKILL.md, references/rule.md).\n
- Boundary markers: Absent; no specific delimiters or warnings are provided to the agent regarding the untrusted nature of the sitemap content.\n
- Capability inventory: Network fetching of arbitrary URLs and cross-referencing with search engine console data.\n
- Sanitization: Absent.\n- [DATA_EXFILTRATION]: The skill performs network operations to fetch sitemaps and verify status codes from arbitrary external domains. It also references official documentation from Google's developer site.
Audit Metadata