web-design-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external URLs, which represents a surface for indirect prompt injection attacks.
  • Ingestion points: The agent is directed to gather context from target URLs and inspect live website content (SKILL.md, Step 1 & 2).
  • Boundary markers: The instructions do not define clear delimiters or warnings to ignore potentially malicious instructions embedded within the HTML, CSS, or text of the target websites.
  • Capability inventory: The skill workflow includes tracing issues to the source code and performing fixes (SKILL.md, Step 4 & 5), granting the agent file-write capabilities that could be targeted by a malicious site.
  • Sanitization: There are no requirements for sanitizing or filtering the content retrieved from external websites before the agent processes it for decision-making.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — web-design-reviewer