web-design-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external, potentially untrusted URLs and has the capability to modify local source code based on that input. This creates a surface for indirect prompt injection where an attacker could embed malicious instructions in a website's metadata or hidden HTML elements to influence the agent's code modifications.
  • Ingestion points: External website content retrieved via target URL (SKILL.md).
  • Boundary markers: None specified for the ingested web content.
  • Capability inventory: File system modification for applying framework-specific code fixes (SKILL.md, references/framework-fixes.md).
  • Sanitization: None specified; the skill relies on visual and structural analysis of raw web content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — web-design-reviewer