create-component

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill workflow utilizes the WebSearch tool to research industry best practices and accessibility patterns for components. Ingesting data from external, untrusted web sources creates a surface for indirect prompt injection, where malicious instructions on a website could potentially influence the agent's output or design decisions.
  • [DATA_EXPOSURE]: The instructions contain hardcoded absolute file paths pointing to a specific user's directory (/Users/sanchitkumar/Downloads/new_folder/...). This exposes internal details of the skill author's local environment but does not involve the exfiltration of sensitive credentials or private user data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 01:53 PM
Security Audit — agent-trust-hub — create-component