skills/yray/skills/pricing-page/Gen Agent Trust Hub

pricing-page

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-supplied business information (such as plan names, pricing, and testimonials) to generate page outlines and technical specifications. This creates a surface for indirect prompt injection where malicious instructions embedded in the user-provided data could influence the agent's output behavior.\n
  • Ingestion points: Business details gathered in the 'Before you design/write' section of SKILL.md, including Offer, Plans, Objections, and Proof fields.\n
  • Boundary markers: Absent; the instructions do not specify delimiters or instructions to ignore embedded commands in the user data.\n
  • Capability inventory: Generation of text-based page outlines, pricing table specifications, FAQ lists, and SEO/AEO metadata schemas.\n
  • Sanitization: No sanitization or validation logic is defined for the external content provided by the user.\n- [SAFE]: The provided demo implementation (demo/index.html) is restricted to client-side HTML, CSS, and JavaScript. It uses standard browser APIs for UI interactions and visual effects (HTML5 Canvas) and does not utilize external dependencies, perform network activity, or access the host file system.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 03:08 AM
Security Audit — agent-trust-hub — pricing-page