agency-onboard
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches content from user-provided external URLs and passes this untrusted data to multiple subagents for analysis. Maliciously crafted content on audited websites (such as hidden text or comments) could attempt to manipulate the audit results or subagent instructions.
- Ingestion points: Multiple
WebFetchcalls in Phase 1 (Discovery) and within the Marketing, Reputation, GEO/SEO, and Legal subagent prompts inSKILL.md. - Boundary markers: Absent. While a
COMPANY CONTEXTblock is used, there are no explicit delimiters or instructions to the agents to disregard potentially malicious commands embedded within the retrieved website content. - Capability inventory: The skill uses
WebFetchandWebSearchfor data gathering, theAgenttool for parallel processing, and performs file system writes to save the final report. - Sanitization: Absent. The skill extracts information directly from the fetched web content without visible filtering or sanitization of potential command patterns.
Audit Metadata