security-headers
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to inventory inline scripts, styles, and third-party domains by analyzing the user's codebase. This creates a potential surface where malicious instructions hidden in the files being audited could influence the agent's behavior.
- Ingestion points: Reads repository files and inventories project assets using the
repo-filestool (SKILL.md). - Boundary markers: The instructions do not specify explicit delimiters or "ignore instructions" warnings for the data extracted from project files.
- Capability inventory: The skill uses the
repo-filestool to read local data and generates configuration snippets fornext.configheaders. - Sanitization: There is no mention of sanitizing or escaping the content retrieved from scripts or styles before it is incorporated into the agent's reasoning for CSP generation.
Audit Metadata