html-to-interaction-prompts
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves ingesting and analyzing untrusted content from external HTML files and live websites (e.g., Framer marketplace pages).
- Ingestion points: The skill processes user-supplied HTML files and navigates to live URLs provided as references.
- Boundary markers: The instructions do not define clear boundaries or 'ignore' directives when processing external content to prevent the agent from inadvertently executing instructions embedded within the source HTML.
- Capability inventory: The agent performs file system writes (creating dated article folders), executes version control commands (
git status,git add), uses media analysis tools (ffprobe), and may serve content onlocalhost. - Sanitization: The instructions focus on extracting interaction data and visual evidence but do not specify sanitization routines to neutralize potential malicious prompts inside the analyzed HTML.
- [COMMAND_EXECUTION]: The skill uses various command-line utilities to manage files and verify media assets.
- Evidence: Calls to
git status,git diff --check,git add -f, andffprobeare integrated into the verification and commit workflows.
Audit Metadata