sitemap-4xx

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external XML sitemaps and the URLs contained within them, which presents a surface for indirect prompt injection where malicious instructions could be embedded in the external data.\n
  • Ingestion points: XML sitemaps and content from extracted URLs (SKILL.md, references/rule.md).\n
  • Boundary markers: Absent; no specific delimiters or warnings are provided to the agent regarding the untrusted nature of the sitemap content.\n
  • Capability inventory: Network fetching of arbitrary URLs and cross-referencing with search engine console data.\n
  • Sanitization: Absent.\n- [DATA_EXFILTRATION]: The skill performs network operations to fetch sitemaps and verify status codes from arbitrary external domains. It also references official documentation from Google's developer site.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:30 AM
Security Audit — agent-trust-hub — sitemap-4xx