audit-website

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites and uses the resulting report to autonomously drive code modifications through an iterative fix loop.
  • Ingestion points: External data is fetched by the squirrel audit command and presented to the agent in the llm output format as described in SKILL.md.
  • Boundary markers: The output format uses XML tags (<rule>, <issues>, <summary>) to provide structural separation between the audit data and the agent's instructions, as detailed in references/OUTPUT-FORMAT.md.
  • Capability inventory: The skill uses the Edit, Bash(squirrel:*), and Read tools to analyze project files and apply modifications based on the external audit findings.
  • Sanitization: According to references/OUTPUT-FORMAT.md, all text content generated in the reports is XML-escaped to prevent structural confusion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:51 PM
Security Audit — agent-trust-hub — audit-website