interview
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill provides a structured interface for human input (text and images) which is then returned to the agent in JSON format. This represents a standard surface for indirect prompt injection where a user's response could influence the agent's subsequent logic.
- Ingestion points:
server.pyhandles POST requests from the HTML form;tui.pyhandles user input via Textual widgets. - Boundary markers: The skill returns data as a structured JSON object, providing clear boundaries for the agent.
- Capability inventory: The skill is capable of writing session data to the local
sessions/directory viainterview.py. - Sanitization: The skill performs basic HTML escaping for code blocks in
server.py, though it lacks rigorous escaping for all user-provided labels in the HTML view. - [EXTERNAL_DOWNLOADS]: The HTML form template (
templates/form.html) loads the Tailwind CSS library fromcdn.tailwindcss.com, which is a well-known and trusted service. - [SAFE]: User responses and session metadata are stored locally in the
sessions/folder within the skill directory for recovery purposes, which is standard behavior for local agent utilities.
Audit Metadata