formkit
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to access and process external documentation from the formkit.com domain.
- Ingestion points: The
references/docs-index.mdfile contains a comprehensive list of documentation URLs pointing to Markdown files onhttps://formkit.com. The skill workflow inSKILL.mdexplicitly directs the agent to open these pages. - Boundary markers: The skill does not provide specific delimiters or instructions to ignore potential instructions embedded within the external documentation content, which could lead to accidental obedience if the remote content is compromised.
- Capability inventory: The skill itself does not define dangerous capabilities like direct shell access, but the agent environment typically includes file system and network tools that could be targeted by instructions found in external data.
- Sanitization: There are no verification steps or sanitization procedures defined for the content retrieved from the documentation URLs.
Audit Metadata