umbraco-dynamic-root

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the WebFetch tool to retrieve the latest extension guidelines from official Umbraco documentation sites (docs.umbraco.com). These references are consistent with the skill's purpose and target the vendor's own verified infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external documentation to inform code generation.
  • Ingestion points: URLs provided in the Documentation section (SKILL.md).
  • Boundary markers: None explicitly defined for the fetching process.
  • Capability inventory: Read, Write, Edit, WebFetch (SKILL.md).
  • Sanitization: None described for external documentation content.
  • While fetching external data creates a surface for indirect prompt injection, the risk is mitigated by the use of trusted official documentation sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:59 AM
Security Audit — agent-trust-hub — umbraco-dynamic-root