article-magazine

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes common external CSS and font resources from well-known services for its visual layout.
  • Evidence: The example.html file includes references to https://cdn.tailwindcss.com and https://fonts.googleapis.com. These are recognized CDNs for frontend development and do not represent a security risk in this context.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it processes user-provided Markdown into HTML format.
  • Ingestion points: User content is interpolated into the magazine template specified in SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters to isolate user-provided content from the processing instructions.
  • Capability inventory: The skill's functionality is limited to generating static HTML layouts for blog and marketing scenarios.
  • Sanitization: No specific escaping or sanitization instructions are provided to the agent for handling user input during interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:57 PM
Security Audit — agent-trust-hub — article-magazine