html-research-reports

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to synthesize data from untrusted external sources such as Slack, web content, and git history, creating an indirect prompt injection surface. However, it includes proactive security guidelines to mitigate common risks.\n
  • Ingestion points: Multi-source research data including Slack, web, and git history (SKILL.md).\n
  • Boundary markers: None explicitly defined to isolate external content.\n
  • Capability inventory: File system access used for writing .html reports to the local disk (SKILL.md).\n
  • Sanitization: Explicitly mandates the use of textContent and document.createElement instead of innerHTML to prevent cross-site scripting (XSS) when incorporating variables or external data into the generated reports (SKILL.md).\n- [EXTERNAL_DOWNLOADS]: The skill allows for the inclusion of Google Fonts via tags. This reference to a well-known service is considered safe.\n- [COMMAND_EXECUTION]: The skill requires the agent to perform file system operations to save output as .html files, which is consistent with its primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:18 AM
Security Audit — agent-trust-hub — html-research-reports