generate-import-html
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The agent is instructed to use shell commands (mkdir -p, cp -r) to create directories and move image assets to the correct output location as part of the HTML generation workflow.
- [PROMPT_INJECTION]: The skill manages an indirect prompt injection surface by processing external data from cleaned.html and metadata.json. It includes mandatory boundary instructions in the 'External Content Safety' section to ensure the agent treats external content as untrusted data and ignores any embedded commands.
- [SAFE]: The file operations and data processing tasks are consistent with the skill's role as an AEM content migration tool, and no evidence of malicious intent or unauthorized data exfiltration was found.
Audit Metadata