reviewing-hi-fi

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes well-known, trusted industry tools such as Playwright and axe-core for browser automation and accessibility auditing.\n- [REMOTE_CODE_EXECUTION]: The skill is designed to render and execute UI code provided by users for the purpose of review. This behavior is the primary function of the skill and is handled through standard headless browser instrumentation.\n- [PROMPT_INJECTION]: While the skill processes untrusted external design code which presents a surface for indirect prompt injection, it mitigates this risk through a structured evaluation workflow and a vision-based review process that focuses on objective rendering artifacts rather than instruction following.\n- [SAFE]: The workflow incorporates security-conscious instructions, specifically requiring the agent to independently re-render all code to prevent being misled by potentially stale or tampered screenshots provided by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 05:47 AM
Security Audit — agent-trust-hub — reviewing-hi-fi