workflow-artifact
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill constructs self-contained HTML files incorporating project data and embedded JavaScript, creating a surface where malicious content in source files could be executed in a browser context.\n- Ingestion points: Project evidence and task-related data are used to generate HTML artifacts (SKILL.md).\n- Boundary markers: No specific instructions are provided to delimit untrusted data from the report structure.\n- Capability inventory: The skill is authorized to read project assets and write new HTML files to the filesystem (SKILL.md).\n- Sanitization: The instructions rely on the agent's internal inspection and factual verification rather than technical sanitization or escaping of embedded content.
Audit Metadata