company-logos
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface in
demo/PROMPT.mdwhere the agent is instructed to ingest and analyze external content. - Ingestion points: The agent is directed to use
https://neuform.ai/pages/fluid-protocol-flow-analytics/index.htmlas a visual and interaction reference. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are present around the reference ingestion.
- Capability inventory: The skill is scoped to design and HTML/CSS generation; no high-risk capabilities such as arbitrary shell execution or credential access were detected.
- Sanitization: No explicit sanitization or filtering logic is provided for the external reference content.
- [EXTERNAL_DOWNLOADS]: The demo configuration in
demo/source.jsonspecifies several runtime dependencies from well-known and trusted providers. - Trusted Sources: Runtime scripts are fetched from
cdnjs.cloudflare.com,cdn.tailwindcss.com, andcode.iconify.design. - Resource Types: The skill uses standard web libraries including Tailwind CSS, GSAP, Three.js, and Iconify Icons.
- [SAFE]: The file
demo/index.htmlcontains a large Base64-encoded string (encodedHtml) representing the demo's HTML document. - Content Analysis: Decoding the string reveals legitimate HTML, CSS, and JavaScript for a UI component demo titled "Fluid Protocol | Flow Analytics".
- Purpose: The encoding is used to package the demo code for injection into a sandboxed
iframeviasrcdoc, which is a common security pattern for previewing AI-generated designs.
Audit Metadata