skills/editframe/skills/editor-gui/Gen Agent Trust Hub

editor-gui

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines components like ef-text and ef-hierarchy that are designed to display data provided to them. If an agent populates these components with untrusted data from external sources, it could be susceptible to indirect prompt injection where instructions embedded in the data influence the agent's behavior.
  • Ingestion points: The content of ef-text elements and item labels within the ef-hierarchy component as described in SKILL.md.
  • Boundary markers: The documentation does not provide specific delimiters or guidance for distinguishing between data and instructions when populating these UI components.
  • Capability inventory: The skill provides significant capabilities, including the ef-workbench.exportVideo() method to render compositions to MP4 files and ef-canvas for manipulating element layouts.
  • Sanitization: There is no mention of built-in sanitization, escaping, or validation for the text and data rendered by these custom elements.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:13 PM
Security Audit — agent-trust-hub — editor-gui