structured-artifact
Pass
Audited by Gen Agent Trust Hub on Oct 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to build HTML artifacts that interpolate data into the DOM using
innerHTML(e.g., incard-grid.mdandtree-and-toc.md). Additionally,diagrams.mdrecommends setting Mermaid'ssecurityLeveltolooseto enable JavaScript callbacks. - Ingestion points: Data items provided by the agent to populate cards, tables, trees, and Mermaid diagrams.
- Boundary markers: None provided in the templates; no instructions are given to the agent to include delimiters or safety warnings for embedded content.
- Capability inventory: The resulting artifacts can execute arbitrary JavaScript in the user's browser context via XSS or Mermaid click callbacks.
- Sanitization: Absent; the templates do not include logic to escape or sanitize input data before it is rendered into the HTML structure.
- [COMMAND_EXECUTION]:
resources/layout-and-theme.mdcontains a shell snippet intended for developer use that finds an available port using a Python one-liner and serves the generated artifacts using Python'shttp.serverandtailscale serve. - [EXTERNAL_DOWNLOADS]: The skill fetches various visualization and styling libraries (Tailwind CSS, Mermaid, Chart.js, Tabulator, Diff2Html, React, and vis-timeline) from well-known CDNs such as jsDelivr and Unpkg, and from official GitHub release repositories.
Audit Metadata