html
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied descriptions to generate functional HTML files containing JavaScript. This creates a vulnerability surface where a user could potentially trick the agent into including malicious logic in the generated code.
- Ingestion points: Arbitrary user descriptions provided as input for artifact generation (SKILL.md).
- Boundary markers: The instructions lack delimiters or explicit warnings to ignore instructions embedded within the user data.
- Capability inventory: The skill generates HTML/JavaScript artifacts that can execute code in a browser context.
- Sanitization: There are no instructions to sanitize or escape user content before interpolating it into the generated JavaScript or HTML structure.
Audit Metadata