geo-audit

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and analyzes data from external websites, creating a surface for indirect prompt injection where a malicious site could influence the agent's output or actions.
  • Ingestion points: External website content, including meta tags, headers, and body content, is retrieved using the WebFetch tool during Phase 1 (Discovery and Reconnaissance).
  • Boundary markers: The instructions lack specific requirements for the agent to use delimiters or explicit 'ignore embedded instructions' warnings when processing the fetched content.
  • Capability inventory: The skill is granted powerful capabilities including Bash, Write, and WebFetch access, which could be misused if the agent is manipulated by external content.
  • Sanitization: There is no mention of sanitizing, filtering, or escaping the external content before it is passed to specialized subagents for analysis.
  • [COMMAND_EXECUTION]: The skill includes Bash in its allowed-tools list. While intended for processing audit data, the combination of shell access and the ingestion of untrusted external data (as noted in the indirect prompt injection analysis) represents a potential risk if command construction is influenced by the fetched content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:50 PM
Security Audit — agent-trust-hub — geo-audit