digits-fintech-swiss-template

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow for ingesting untrusted user data to populate an HTML template, creating a surface for indirect prompt injection.\n- Ingestion points: Workflow in SKILL.md requires replacing copy and metrics from user input.\n- Boundary markers: The output is encapsulated in <artifact> tags, though specific delimiters for untrusted data within the template are not defined.\n- Capability inventory: The skill utilizes the file_write capability to produce the output artifact.\n- Sanitization: The references/checklist.md enforces the exclusion of sandbox-hostile APIs such as localStorage and window.open in the generated content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:57 PM
Security Audit — agent-trust-hub — digits-fintech-swiss-template