landing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided product names and pitches, interpolating them into the final HTML output and CLI arguments for local scripts. Ingestion occurs in Phase 0 of SKILL.md. No explicit sanitization of this input is described, although structural validation is performed by html_validator.py.
  • [COMMAND_EXECUTION]: Local Python scripts (brand_palette_validator.py, kebab_slug_generator.py, html_validator.py) are executed to process input and validate the generated file.
  • [EXTERNAL_DOWNLOADS]: The skill references font and animation assets from well-known services: fonts.googleapis.com and cdnjs.cloudflare.com.
  • [DYNAMIC_EXECUTION]: The skill generates a self-contained HTML file containing JavaScript code for animations based on predefined GSAP patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:23 PM
Security Audit — agent-trust-hub — landing