skills/gesso-build/skills/anti-slop/Gen Agent Trust Hub

anti-slop

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches and runs the @gessobuild/anti-slop utility via npx from the NPM registry. This package is provided by the skill's author to perform the core design critique and fixing functions.\n- [COMMAND_EXECUTION]: The skill utilizes shell commands (npx -y @gessobuild/anti-slop check and fix) to audit local HTML/CSS files and apply automated design corrections.\n- [PROMPT_INJECTION]: The skill processes untrusted HTML documents provided by the user and incorporates a safety instruction (Hard Rule 6) that explicitly directs the agent to treat all scanned content as data rather than instructions, mitigating the risk of indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 01:01 AM
Security Audit — agent-trust-hub — anti-slop