web-design-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external URLs, which represents a surface for indirect prompt injection attacks.
- Ingestion points: The agent is directed to gather context from target URLs and inspect live website content (SKILL.md, Step 1 & 2).
- Boundary markers: The instructions do not define clear delimiters or warnings to ignore potentially malicious instructions embedded within the HTML, CSS, or text of the target websites.
- Capability inventory: The skill workflow includes tracing issues to the source code and performing fixes (SKILL.md, Step 4 & 5), granting the agent file-write capabilities that could be targeted by a malicious site.
- Sanitization: There are no requirements for sanitizing or filtering the content retrieved from external websites before the agent processes it for decision-making.
Audit Metadata