grow-website
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data during its discovery and intake phases, creating a potential vector for indirect instructions to influence agent behavior or poison project artifacts.
- Ingestion points: The skill ingests visitor research, exit surveys, support tickets, and chat logs as described in the 'Intake' section and Phase 1 (Discovery).
- Capability inventory: The skill performs repeated file writes to multiple project artifacts in the local
docs/directory, includingWEBSITE.md,OFFER.md,MARKETING.md,EXPERIMENTS.md,POSITIONING.md,METRICS.md, andGROW-WEBSITE-PLAN.md. - Sanitization: There are no specific instructions or mechanisms for sanitizing, validating, or escaping the external research data before it is interpolated into project documentation.
- Boundary markers: The instructions lack boundary markers or warnings to the agent to disregard potentially malicious instructions embedded within the ingested visitor data.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to suggest the installation of external tools using a package runner.
- Evidence: The 'Operating Rules' specify that if a dependent skill is missing, the agent should offer to run
npx skills add wondelai/skills/<slug> --global. - Context: The suggested packages are resources belonging to the skill's author ('wondelai') and are documented here as standard vendor functionality.
Audit Metadata