platform-widget-generate
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the user's prompt to define the structure and content of generated UI widgets.
- Ingestion points: The skill explicitly instructs the agent to infer the widget shape directly from the user's prompt (e.g., pasted JSON payloads or descriptive prose) in the absence of a pre-defined schema.
- Boundary markers: The instructions do not define delimiters or specific warnings to prevent the agent from following instructions embedded within the user's UI descriptions.
- Capability inventory: The skill possesses the capability to write files to the local file system and execute metadata actions. The generated widgets can perform actions like opening external URLs or sending messages back to the agent.
- Sanitization: Although formula functions like
HTMLENCODEandJSENCODEare documented, there is no mandatory sanitization step for the user-provided data during the initial shape inference and widget authoring process.
Audit Metadata