html-to-interaction-prompts

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze untrusted HTML, CSS, and JavaScript from local files or live URLs to generate interaction prompts. This creates an attack surface where malicious instructions could be hidden within the source code (e.g., in HTML comments, metadata, or scripts) to influence the agent's output or actions during the article generation and commit process.
  • Ingestion points: The workflow involves reading user-provided HTML, CSS, and scripts from local files, exported pages, or live web references (SKILL.md, Workflow step 1).
  • Boundary markers: The instructions do not specify the use of clear delimiters or instructions for the agent to ignore natural language commands that may be embedded within the source HTML.
  • Capability inventory: The agent is authorized to capture media (screenshots and video), write markdown articles to the file system, and perform Git operations like staging and committing files (SKILL.md, Workflow steps 4-8).
  • Sanitization: There are no described mechanisms for sanitizing or filtering the content of the source HTML files to detect or neutralize potential injection attempts before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:31 AM
Security Audit — agent-trust-hub — html-to-interaction-prompts