eli5
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data by interpolating the
$ARGUMENTSvariable into the system prompt. - Ingestion points: The
SKILL.mdfile uses the$ARGUMENTSplaceholder to accept user-provided topics. - Boundary markers: The skill does not use specific delimiters or instructions to prevent the agent from following instructions that might be embedded within the user-provided topic.
- Capability inventory: The skill is limited to generating an HTML artifact for explanation purposes; it contains no subprocess calls, file-write operations, or network access.
- Sanitization: There is no evidence of input validation or sanitization for the provided arguments.
Audit Metadata