overdrive
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructions for frontend development using standard web technologies. All described techniques are standard for high-performance web development and operate within the browser security sandbox.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided project context to guide UI generation and utilizes browser automation for visual verification. While this presents an ingestion surface for untrusted data, the risk is mitigated by a human-in-the-loop requirement to propose directions before building and the skill's focus on presentation layers. Evidence: 1. Ingestion points: project goals and personality in MANDATORY PREPARATION section. 2. Boundary markers: Absent. 3. Capability inventory: browser automation for previewing work. 4. Sanitization: Absent.
- [DATA_EXPOSURE]: Mentions of browser device APIs (e.g., geolocation) are accompanied by explicit instructions to seek user permission and use them sparingly, adhering to standard security best practices.
- [COMMAND_EXECUTION]: Instructions to use browser automation tools are focused on visually verifying generated UI components, representing a legitimate functional capability for a development agent rather than a command execution vulnerability.
Audit Metadata