umbraco-validation-context

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch implementation guidelines from official Umbraco documentation domains (docs.umbraco.com) to ensure the validation logic adheres to current foundation and extension registry standards.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates for building forms that ingest user input, creating a potential surface for indirect prompt injection. * Ingestion points: User-facing input fields like 'name', 'email', 'city', and 'country' defined in the Lit components within SKILL.md. * Boundary markers: No specific delimiters or instructions are provided to the agent to isolate these user-controlled values from the rest of the application context. * Capability inventory: The skill manifest grants access to WebFetch, Read, Write, and Edit tools, which could be leveraged if the agent follows malicious instructions embedded in field data. * Sanitization: The examples rely on default Lit framework escaping for UI rendering and use JSON.stringify for diagnostic output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:59 AM
Security Audit — agent-trust-hub — umbraco-validation-context