doc-kami-parchment
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and loads resources from well-known technology services to provide styling and typography.
- Fetches the Tailwind CSS framework via the official CDN (cdn.tailwindcss.com).
- Imports multiple serif and mono font families from Google Fonts (fonts.googleapis.com).
- [PROMPT_INJECTION]: The skill acts as a transformation layer for user-supplied data, which introduces a surface for indirect prompt injection.
- Ingestion points: User content is processed and interpolated into the Kami Parchment template (SKILL.md).
- Boundary markers: Absent. The instructions do not define specific delimiters to separate user content from the styling instructions.
- Capability inventory: The skill is limited to document formatting and does not demonstrate capabilities for file system modification, shell command execution, or network exfiltration in its own scripts.
- Sanitization: Absent. There is no explicit instruction to sanitize or filter user-provided content prior to document generation.
Audit Metadata