html-to-interaction-prompts

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves ingesting and analyzing untrusted content from external HTML files and live websites (e.g., Framer marketplace pages).
  • Ingestion points: The skill processes user-supplied HTML files and navigates to live URLs provided as references.
  • Boundary markers: The instructions do not define clear boundaries or 'ignore' directives when processing external content to prevent the agent from inadvertently executing instructions embedded within the source HTML.
  • Capability inventory: The agent performs file system writes (creating dated article folders), executes version control commands (git status, git add), uses media analysis tools (ffprobe), and may serve content on localhost.
  • Sanitization: The instructions focus on extracting interaction data and visual evidence but do not specify sanitization routines to neutralize potential malicious prompts inside the analyzed HTML.
  • [COMMAND_EXECUTION]: The skill uses various command-line utilities to manage files and verify media assets.
  • Evidence: Calls to git status, git diff --check, git add -f, and ffprobe are integrated into the verification and commit workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — html-to-interaction-prompts