geo-citability

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data retrieved from arbitrary web URLs, which exposes the agent to potential indirect prompt injection attacks if the fetched pages contain malicious instructions.
  • Ingestion points: External web content is retrieved using the WebFetch tool as specified in Step 1 of the Analysis Procedure within SKILL.md.
  • Boundary markers: Absent; there are no explicit delimiters or strict structural guardrails defined to prevent instructions embedded in the web content from being executed or obeyed by the agent.
  • Capability inventory: The skill configuration allows the use of Write (to generate the score report) and Bash tools, though the text itself does not define any dynamic shell command assembly using the fetched web content.
  • Sanitization: Absent; no input sanitization, filtering, or escaping mechanisms are described for the fetched content before segmentation and scoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:50 PM
Security Audit — agent-trust-hub — geo-citability