webdev
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill inherently possesses an attack surface for indirect prompt injection as it is designed to audit web pages for accessibility and performance, and integrate with external CMS and API data. However, the skill provides strong defensive instructions to mitigate these risks:
- Ingestion points: The agent reads data from external URLs provided by users (accessibility/performance audits) and processes payloads from external APIs and CMS platforms (backend/cms modes).
- Boundary markers: The instructions in
references/backend.mdandSKILL.mdexplicitly command the agent to 'treat third-party responses as untrusted' and 'validate ALL input at the boundary'. - Capability inventory: The skill uses
bash,run_command, andwrite_to_fileto implement features. - Sanitization: The skill mandates the use of parameterized queries or typed ORMs to prevent SQL injection, strict DTO/Zod schema validation to prevent mass assignment, and maintains a blacklist of private/cloud-metadata IP addresses to prevent SSRF (Server-Side Request Forgery).
- [EXTERNAL_DOWNLOADS]: The
README.mdfile provides installation instructions usingnpx skills add harshsinghmp/muse-skills. This is the standard installation method for the platform and references the author's own repository, representing a safe and expected external reference for skill distribution. - [SAFE]: The skill includes advanced security logic in
references/backend.mdunder the 'In-Dev Web Security Prevention Rules' section. These rules provide clear instructions to prevent Broken Object Level Authorization (BOLA), SSRF, and SQL Injection, which significantly enhances the security posture of the generated code.
Audit Metadata