skills/0juano/agent-skills/trmnl-dev/Gen Agent Trust Hub

trmnl-dev

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or obfuscation techniques were detected in the skill instructions or referenced files. The documentation reflects standard practices for integrating with the TRMNL platform.
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of external data from webhooks and merge variables, which constitutes an inherent surface for indirect prompt injection. This is associated with the primary purpose of rendering dynamic content.
  • Ingestion points: Webhook payload processing in SKILL.md and variable retrieval via MergeVariablesShowTool in references/mcp.md.
  • Boundary markers: No explicit delimiters are suggested for isolating instructions within user-provided merge variables.
  • Capability inventory: The MarkupsWriteTool in references/mcp.md enables updating plugin markup on the live TRMNL service.
  • Sanitization: The instructions recommend unescaping data retrieved from the MCP before usage or comparison.
  • [EXTERNAL_DOWNLOADS]: The documentation references standard libraries such as liquidjs and official TRMNL CDN assets for local development and previewing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 09:10 AM
Security Audit — agent-trust-hub — trmnl-dev