skills/umbraco/umbraco-cms-backoffice-skills/umbraco-entity-create-option-action/Gen Agent Trust Hub
umbraco-entity-create-option-action
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS] (SAFE): The skill utilizes the WebFetch tool to retrieve documentation from official Umbraco domains (docs.umbraco.com). These sources are appropriate for the skill's stated purpose of assisting with Umbraco backoffice development.
- [PROMPT_INJECTION] (LOW): The skill exhibits an indirect prompt injection surface (Category 8).
- Ingestion points: The workflow explicitly instructs the agent to use WebFetch on external Umbraco documentation URLs.
- Boundary markers: No specific boundary markers or instructions to ignore embedded prompts within the fetched documentation are present.
- Capability inventory: The agent has 'Write' and 'Edit' permissions to generate files based on the ingested content.
- Sanitization: No sanitization or validation of the fetched content is specified before it is used for code generation.
Audit Metadata