frame-liquid-bg-hero

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The template fetches the Tailwind CSS framework from cdn.tailwindcss.com and typography from fonts.googleapis.com. Both are well-known services commonly used for web development.
  • [EXTERNAL_DOWNLOADS]: The skill instructions suggest using jsdelivr (a well-known CDN) to load the regl library if the high-end WebGL implementation path is selected.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to how it handles user-provided data.
  • Ingestion points: The skill takes user-supplied quotes, titles, and data to populate the generated HTML (found in SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions to treat user input as untrusted data in the prompt interpolation process.
  • Capability inventory: The skill generates executable HTML and JavaScript code meant for browser rendering.
  • Sanitization: The instructions do not specify any escaping or sanitization requirements for the user-provided text before it is inserted into the HTML structure, which could allow for the injection of malicious scripts if the input is not handled carefully by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — frame-liquid-bg-hero