prototype
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill explicitly mandates that all generated prototype artifacts (SVG and HTML) must be self-contained. It strictly prohibits external requests of any kind, including CDNs, remote fonts, or linked assets, which prevents data leakage or tracking when a user opens the generated files.
- [COMMAND_EXECUTION]: The skill interacts with host-provided design-file backends. It implements a robust safety protocol that requires the agent to read the application state, identify the active document, and receive an explicit user confirmation before writing any data. This prevents unauthorized modification of existing work or writing to unintended file paths.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources such as
jtbd.jsonand user-provided descriptions to generate mockup content. While this is necessary for its function, it represents a surface where adversarial data could attempt to influence the layout or instructions of the prototype. - [DYNAMIC_EXECUTION]: For high-fidelity HTML prototypes, the skill allows for the inclusion of minimal inline JavaScript if an interaction requires state management. The skill requires that such scripts be documented as scaffolding in the artifact's notes, providing transparency to the end-user.
Audit Metadata