skills/ethan-rio/skills/html-mind-map/Gen Agent Trust Hub

html-mind-map

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates an interactive workflow where user input (mind map labels and structure) is captured in an HTML file and submitted back to the agent. This creates a surface for indirect prompt injection.
  • Ingestion points: User-modified node labels and branch structures in the generated HTML artifact.
  • Boundary markers: None specified for the submission JSON envelope.
  • Capability inventory: The 'submitToClaude' function enables the transmission of captured state back to the AI agent's session context for further processing.
  • Sanitization: While the skill explicitly instructs the AI to avoid XSS by using 'textContent' instead of 'innerHTML', it does not define specific sanitization for the agent when interpreting the returned data.
  • [EXTERNAL_DOWNLOADS]: The skill allows for loading assets from well-known technology services.
  • Evidence: The instructions permit using Google Fonts via <link> tags for aesthetic purposes.
  • Context: References to Google's infrastructure for fonts are standard practice and originate from a trusted service.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:18 AM
Security Audit — agent-trust-hub — html-mind-map