geo-llmstxt

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted data from external domains via the WebFetch tool.
  • Ingestion points: The agent is instructed to fetch and analyze external llms.txt files, site metadata, navigation structures, and page content (paragraphs and headers) to validate or generate documentation.
  • Boundary markers: The instructions provide no specific boundary markers (such as XML tags or unique delimiters) to separate external website content from the agent's internal reasoning or to warn the agent to ignore instructions embedded in the crawled data.
  • Capability inventory: The skill is granted access to the Bash, Write, and WebFetch tools, providing a path for potential command execution or file modification if the agent is manipulated by adversarial content found on a website.
  • Sanitization: There is no process defined to sanitize or filter the fetched HTML and text for malicious patterns or prompt injection payloads before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:51 PM
Security Audit — agent-trust-hub — geo-llmstxt