landing-page-mastery
Pass
Audited by Gen Agent Trust Hub on Feb 21, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill defines a 'Flujo de Auditoría' (Audit Flow) that instructs the agent to process external URLs or screenshots provided by users to perform a 100-point check.
- Ingestion points:
SKILL.md(Audit Flow, Step 1) andreferences/audit-checklist.mdrequest the agent to analyze external content. - Boundary markers: Absent. The instructions do not include delimiters or specific warnings to ignore instructions embedded within the target landing pages.
- Capability inventory: None. The skill package contains no scripts (.py, .js, .sh), limiting the direct impact of an injection to the current conversation context.
- Sanitization: Absent. There is no logic provided to filter or escape content retrieved from external URLs.
- [Metadata Poisoning] (SAFE): The skill metadata (name, description, author) is consistent with the stated purpose and contains no hidden instructions or deceptive patterns.
Audit Metadata