restaurant-online

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Potential for indirect prompt injection via external web content.
  • Ingestion points: The skill uses WebSearch to gather information from Google Business Profile, Yelp, restaurant websites, and delivery platforms (Uber Eats, DoorDash, etc.) in SKILL.md.
  • Boundary markers: No explicit delimiters or 'ignore embedded instructions' warnings are present for the ingested data.
  • Capability inventory: The agent has the capability to write a markdown report to the local filesystem (RESTAURANT-ONLINE-[Name].md).
  • Sanitization: There is no evidence of input validation or sanitization for the content retrieved from web searches.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 12:03 PM
Security Audit — agent-trust-hub — restaurant-online