html-design-tokens
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided design data to generate HTML artifacts, creating a potential surface for injection attacks.
- Ingestion points: User-supplied token identifiers, hex values, and type samples are processed by the skill instructions.
- Boundary markers: The instructions require outputting to a standalone
.htmlfile, separating the artifact from the chat application context. - Capability inventory: The skill is authorized to write files to the local disk (
<topic>-<kind>.html). - Sanitization: The skill mandates secure coding practices, explicitly forbidding the use of
innerHTMLfor dynamic content and requiringtextContentanddocument.createElementto prevent XSS. - [COMMAND_EXECUTION]: The skill instructs the agent to create new files on the local filesystem.
- Evidence: "Output a real .html file... write the file... Save with a descriptive name".
- Context: This behavior is the primary intended function of the skill for generating design artifacts.
- [EXTERNAL_DOWNLOADS]: The skill allows for referencing external resources from a well-known service.
- Evidence: "Google Fonts via is fine".
- Context: The skill permits loading font assets from Google's official infrastructure for stylistic purposes.
Audit Metadata