html-design-tokens

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided design data to generate HTML artifacts, creating a potential surface for injection attacks.
  • Ingestion points: User-supplied token identifiers, hex values, and type samples are processed by the skill instructions.
  • Boundary markers: The instructions require outputting to a standalone .html file, separating the artifact from the chat application context.
  • Capability inventory: The skill is authorized to write files to the local disk (<topic>-<kind>.html).
  • Sanitization: The skill mandates secure coding practices, explicitly forbidding the use of innerHTML for dynamic content and requiring textContent and document.createElement to prevent XSS.
  • [COMMAND_EXECUTION]: The skill instructs the agent to create new files on the local filesystem.
  • Evidence: "Output a real .html file... write the file... Save with a descriptive name".
  • Context: This behavior is the primary intended function of the skill for generating design artifacts.
  • [EXTERNAL_DOWNLOADS]: The skill allows for referencing external resources from a well-known service.
  • Evidence: "Google Fonts via is fine".
  • Context: The skill permits loading font assets from Google's official infrastructure for stylistic purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:18 AM
Security Audit — agent-trust-hub — html-design-tokens