webgl-landing-steering
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process user-provided brand adjectives, conversion goals, and technical constraints to generate design recommendations and code templates. This creates a surface where malicious instructions could be embedded in the user's input to influence the agent's behavior.
- Ingestion points: The skill takes input for brand signals, device mix, motion tolerance, and production constraints in SKILL.md (Section 1 and Section 6).
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the prompt templates.
- Capability inventory: No executable tools, scripts, network operations, or file-system write capabilities are detected in this skill.
- Sanitization: The skill does not implement any sanitization or validation for the user-supplied input strings.
Audit Metadata