web-design-reviewer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external, potentially untrusted URLs and has the capability to modify local source code based on that input. This creates a surface for indirect prompt injection where an attacker could embed malicious instructions in a website's metadata or hidden HTML elements to influence the agent's code modifications.
- Ingestion points: External website content retrieved via target URL (SKILL.md).
- Boundary markers: None specified for the ingested web content.
- Capability inventory: File system modification for applying framework-specific code fixes (SKILL.md, references/framework-fixes.md).
- Sanitization: None specified; the skill relies on visual and structural analysis of raw web content.
Audit Metadata