geo-citability
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data retrieved from arbitrary web URLs, which exposes the agent to potential indirect prompt injection attacks if the fetched pages contain malicious instructions.
- Ingestion points: External web content is retrieved using the
WebFetchtool as specified in Step 1 of the Analysis Procedure withinSKILL.md. - Boundary markers: Absent; there are no explicit delimiters or strict structural guardrails defined to prevent instructions embedded in the web content from being executed or obeyed by the agent.
- Capability inventory: The skill configuration allows the use of
Write(to generate the score report) andBashtools, though the text itself does not define any dynamic shell command assembly using the fetched web content. - Sanitization: Absent; no input sanitization, filtering, or escaping mechanisms are described for the fetched content before segmentation and scoring.
Audit Metadata