browsing-styles

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a mechanism to regenerate style tile images which accepts arbitrary text input from the local web interface.
  • Ingestion points: The scripts/preview_server.ts script handles POST requests to the /regenerate/:styleId endpoint, extracting a prompt field from the JSON body.
  • Boundary markers: No specific delimiters or safety instructions are used to wrap the user-provided prompt before it is processed.
  • Capability inventory: The skill possesses network access via the callGeminiImage utility and filesystem write access via the /save-tile/ endpoint which uses writeFile.
  • Sanitization: The input prompt is only subjected to basic whitespace trimming before being sent to the external image generation API.
  • [COMMAND_EXECUTION]: The skill executes local commands to optimize generated assets.
  • Evidence: scripts/generate_tiles.ts and scripts/preview_server.ts use spawnSync to run bun run scripts/optimize-images.ts.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to an external AI service for image generation.
  • Evidence: Calls to callGeminiImage in scripts/generate_tiles.ts and scripts/preview_server.ts interact with the Gemini API to create preview tiles.
  • [DYNAMIC_EXECUTION]: The skill dynamically invokes the system's default browser to display the interactive UI.
  • Evidence: scripts/preview_server.ts uses Bun.spawn to execute platform-specific commands (open, start, or xdg-open) based on the operating system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 10:24 PM