geo-bulk-processor
Pass
Audited by Gen Agent Trust Hub on Mar 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process large-scale external content (URL lists, sitemaps, and CMS exports), creating a potential surface for indirect prompt injection.\n- Ingestion points: Identified in SKILL.md under Step 2 (Ingest and profile the corpus) and in evaluation prompts.\n- Boundary markers: Absent; the skill instructions do not explicitly require the use of delimiters or safety warnings when handling external content.\n- Capability inventory: No high-risk capabilities such as network requests, file system modifications, or subprocess execution are present in the provided skill components.\n- Sanitization: Absent; no validation or sanitization logic is provided for the ingested data.
Audit Metadata