audit-website
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites and uses the resulting report to autonomously drive code modifications through an iterative fix loop.
- Ingestion points: External data is fetched by the
squirrel auditcommand and presented to the agent in thellmoutput format as described inSKILL.md. - Boundary markers: The output format uses XML tags (
<rule>,<issues>,<summary>) to provide structural separation between the audit data and the agent's instructions, as detailed inreferences/OUTPUT-FORMAT.md. - Capability inventory: The skill uses the
Edit,Bash(squirrel:*), andReadtools to analyze project files and apply modifications based on the external audit findings. - Sanitization: According to
references/OUTPUT-FORMAT.md, all text content generated in the reports is XML-escaped to prevent structural confusion.
Audit Metadata