form-validation
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle and validate untrusted user input through the implementation of Zod schemas.
- Ingestion points: User-supplied form data is ingested through various schemas defined in
SKILL.mdand thescripts/schemas/directory (e.g., login, registration, and payment forms). - Boundary markers: Zod schemas act as strict validation boundaries, enforcing type safety and format constraints (such as regex and length checks) before data is processed.
- Capability inventory: The skill and its associated scripts do not possess dangerous capabilities such as file system writing, arbitrary code execution, or unauthorized network exfiltration. Network usage is limited to local API calls for asynchronous validation (e.g., checking username availability).
- Sanitization: The skill focuses on input validation using regex, Luhn algorithm for payments, and type enforcement, which significantly reduces the risk of processing malformed or malicious data strings.
Audit Metadata