web-interface-guidelines
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides a standard set of review guidelines for web development. It does not contain any executable scripts, network requests, or hardcoded credentials.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted source code files for analysis, which creates a potential surface for indirect prompt injection if malicious instructions are embedded within the code being reviewed.
- Ingestion points: The agent reads source files (e.g., .tsx, .vue) from the local project environment.
- Boundary markers: There are no specific delimiters or instructions to ignore embedded prompts within the files being audited.
- Capability inventory: The skill facilitates text-based analysis and reporting within the agent's context.
- Sanitization: No explicit sanitization or filtering of external content is defined in the instructions.
Audit Metadata