doc-kami-parchment

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and loads resources from well-known technology services to provide styling and typography.
  • Fetches the Tailwind CSS framework via the official CDN (cdn.tailwindcss.com).
  • Imports multiple serif and mono font families from Google Fonts (fonts.googleapis.com).
  • [PROMPT_INJECTION]: The skill acts as a transformation layer for user-supplied data, which introduces a surface for indirect prompt injection.
  • Ingestion points: User content is processed and interpolated into the Kami Parchment template (SKILL.md).
  • Boundary markers: Absent. The instructions do not define specific delimiters to separate user content from the styling instructions.
  • Capability inventory: The skill is limited to document formatting and does not demonstrate capabilities for file system modification, shell command execution, or network exfiltration in its own scripts.
  • Sanitization: Absent. There is no explicit instruction to sanitize or filter user-provided content prior to document generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — doc-kami-parchment