vox-explainer

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied research questions and facts to generate dynamic content in an HTML file. (1) Ingestion points: User questions and fact lists are collected in Step 1. (2) Boundary markers: No explicit delimiters or instructions are used to isolate user-provided data within the generated code. (3) Capability inventory: The skill generates an HTML file with JavaScript that handles frame-based seeking and rendering. (4) Sanitization: No explicit sanitization or escaping steps are defined for the user text before interpolation.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the hyperframes tool from the HeyGen organization using npx. The instructions include procedural checks to verify tool existence and require explicit user consent before installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 11:29 PM