windows-3-1-web-designer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the generation of web components, CSS, and UI logic based on user-provided instructions. This inherent functionality creates a surface for indirect prompt injection where malicious instructions could be embedded in the data the agent processes.
- Ingestion points: User-provided application requirements and design descriptions enter the agent context to be transformed into code as described in
SKILL.mdand the reference files. - Boundary markers: The skill does not provide specific instructions for the agent to use delimiters or "ignore embedded instructions" warnings when processing user-provided content for code generation.
- Capability inventory: The skill is configured to allow file system operations via
Read,Write,Edit,Glob, andGreptools, which could be leveraged if an injection attack is successful. - Sanitization: There are no documented procedures for the agent to escape or validate user-provided strings before they are interpolated into the generated HTML, CSS, or JavaScript code.
Audit Metadata