windows-3-1-web-designer

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the generation of web components, CSS, and UI logic based on user-provided instructions. This inherent functionality creates a surface for indirect prompt injection where malicious instructions could be embedded in the data the agent processes.
  • Ingestion points: User-provided application requirements and design descriptions enter the agent context to be transformed into code as described in SKILL.md and the reference files.
  • Boundary markers: The skill does not provide specific instructions for the agent to use delimiters or "ignore embedded instructions" warnings when processing user-provided content for code generation.
  • Capability inventory: The skill is configured to allow file system operations via Read, Write, Edit, Glob, and Grep tools, which could be leveraged if an injection attack is successful.
  • Sanitization: There are no documented procedures for the agent to escape or validate user-provided strings before they are interpolated into the generated HTML, CSS, or JavaScript code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — windows-3-1-web-designer