geo-audit
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches and analyzes data from external websites, creating a surface for indirect prompt injection where a malicious site could influence the agent's output or actions.
- Ingestion points: External website content, including meta tags, headers, and body content, is retrieved using the
WebFetchtool during Phase 1 (Discovery and Reconnaissance). - Boundary markers: The instructions lack specific requirements for the agent to use delimiters or explicit 'ignore embedded instructions' warnings when processing the fetched content.
- Capability inventory: The skill is granted powerful capabilities including
Bash,Write, andWebFetchaccess, which could be misused if the agent is manipulated by external content. - Sanitization: There is no mention of sanitizing, filtering, or escaping the external content before it is passed to specialized subagents for analysis.
- [COMMAND_EXECUTION]: The skill includes
Bashin itsallowed-toolslist. While intended for processing audit data, the combination of shell access and the ingestion of untrusted external data (as noted in the indirect prompt injection analysis) represents a potential risk if command construction is influenced by the fetched content.
Audit Metadata