web-interface-guidelines

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a standard set of review guidelines for web development. It does not contain any executable scripts, network requests, or hardcoded credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted source code files for analysis, which creates a potential surface for indirect prompt injection if malicious instructions are embedded within the code being reviewed.
  • Ingestion points: The agent reads source files (e.g., .tsx, .vue) from the local project environment.
  • Boundary markers: There are no specific delimiters or instructions to ignore embedded prompts within the files being audited.
  • Capability inventory: The skill facilitates text-based analysis and reporting within the agent's context.
  • Sanitization: No explicit sanitization or filtering of external content is defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:06 PM
Security Audit — agent-trust-hub — web-interface-guidelines