html-mind-map
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates an interactive workflow where user input (mind map labels and structure) is captured in an HTML file and submitted back to the agent. This creates a surface for indirect prompt injection.
- Ingestion points: User-modified node labels and branch structures in the generated HTML artifact.
- Boundary markers: None specified for the submission JSON envelope.
- Capability inventory: The 'submitToClaude' function enables the transmission of captured state back to the AI agent's session context for further processing.
- Sanitization: While the skill explicitly instructs the AI to avoid XSS by using 'textContent' instead of 'innerHTML', it does not define specific sanitization for the agent when interpreting the returned data.
- [EXTERNAL_DOWNLOADS]: The skill allows for loading assets from well-known technology services.
- Evidence: The instructions permit using Google Fonts via
<link>tags for aesthetic purposes. - Context: References to Google's infrastructure for fonts are standard practice and originate from a trusted service.
Audit Metadata