structured-artifact

Pass

Audited by Gen Agent Trust Hub on Oct 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to build HTML artifacts that interpolate data into the DOM using innerHTML (e.g., in card-grid.md and tree-and-toc.md). Additionally, diagrams.md recommends setting Mermaid's securityLevel to loose to enable JavaScript callbacks.
  • Ingestion points: Data items provided by the agent to populate cards, tables, trees, and Mermaid diagrams.
  • Boundary markers: None provided in the templates; no instructions are given to the agent to include delimiters or safety warnings for embedded content.
  • Capability inventory: The resulting artifacts can execute arbitrary JavaScript in the user's browser context via XSS or Mermaid click callbacks.
  • Sanitization: Absent; the templates do not include logic to escape or sanitize input data before it is rendered into the HTML structure.
  • [COMMAND_EXECUTION]: resources/layout-and-theme.md contains a shell snippet intended for developer use that finds an available port using a Python one-liner and serves the generated artifacts using Python's http.server and tailscale serve.
  • [EXTERNAL_DOWNLOADS]: The skill fetches various visualization and styling libraries (Tailwind CSS, Mermaid, Chart.js, Tabulator, Diff2Html, React, and vis-timeline) from well-known CDNs such as jsDelivr and Unpkg, and from official GitHub release repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 10, 2026, 03:02 AM