browsing-styles
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a mechanism to regenerate style tile images which accepts arbitrary text input from the local web interface.
- Ingestion points: The
scripts/preview_server.tsscript handles POST requests to the/regenerate/:styleIdendpoint, extracting apromptfield from the JSON body. - Boundary markers: No specific delimiters or safety instructions are used to wrap the user-provided prompt before it is processed.
- Capability inventory: The skill possesses network access via the
callGeminiImageutility and filesystem write access via the/save-tile/endpoint which useswriteFile. - Sanitization: The input prompt is only subjected to basic whitespace trimming before being sent to the external image generation API.
- [COMMAND_EXECUTION]: The skill executes local commands to optimize generated assets.
- Evidence:
scripts/generate_tiles.tsandscripts/preview_server.tsusespawnSyncto runbun run scripts/optimize-images.ts. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to an external AI service for image generation.
- Evidence: Calls to
callGeminiImageinscripts/generate_tiles.tsandscripts/preview_server.tsinteract with the Gemini API to create preview tiles. - [DYNAMIC_EXECUTION]: The skill dynamically invokes the system's default browser to display the interactive UI.
- Evidence:
scripts/preview_server.tsusesBun.spawnto execute platform-specific commands (open,start, orxdg-open) based on the operating system.
Audit Metadata