vibe-nothing-ui-design

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill documentation provides an unsafe code example for rendering dynamic content that is vulnerable to Indirect Prompt Injection (XSS).
  • Ingestion points: The renderAgents function example located in the Dynamic Content section of SKILL.md ingests an external agents data structure.
  • Boundary markers: No markers or delimiters are present to separate instructions from data within the template literal.
  • Capability inventory: The example leverages innerHTML which can execute embedded scripts in the data.
  • Sanitization: There is no sanitization, escaping, or validation of the input data before it is interpolated into the HTML string.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 12:47 PM
Security Audit — agent-trust-hub — vibe-nothing-ui-design