best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends using Cloudflare's cdnjs as a vetted mirror for loading polyfills to mitigate supply-chain risks associated with other third-party services (SKILL.md).\n- [INDIRECT_PROMPT_INJECTION]: The skill's workflow for performing security and quality audits involves processing data from rendered web pages and browser logs, establishing a surface for indirect prompt injection (SKILL.md).\n
- Ingestion points: The agent is instructed to ingest and analyze rendered page content, console logs, and network failures using tools like
lighthouse_auditor the Lighthouse CLI (SKILL.md).\n - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the audited web content.\n
- Capability inventory: The skill enables reading external content via Lighthouse and browser tools, and provides workflows for the agent to modify the application's source code to fix identified issues (SKILL.md).\n
- Sanitization: No explicit sanitization or filtering of the audit input (the external website content) is specified, allowing potential injection attacks to reach the agent's context.
Audit Metadata