frame-liquid-bg-hero
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The template fetches the Tailwind CSS framework from
cdn.tailwindcss.comand typography fromfonts.googleapis.com. Both are well-known services commonly used for web development. - [EXTERNAL_DOWNLOADS]: The skill instructions suggest using
jsdelivr(a well-known CDN) to load theregllibrary if the high-end WebGL implementation path is selected. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to how it handles user-provided data.
- Ingestion points: The skill takes user-supplied quotes, titles, and data to populate the generated HTML (found in
SKILL.md). - Boundary markers: There are no explicit delimiters or instructions to treat user input as untrusted data in the prompt interpolation process.
- Capability inventory: The skill generates executable HTML and JavaScript code meant for browser rendering.
- Sanitization: The instructions do not specify any escaping or sanitization requirements for the user-provided text before it is inserted into the HTML structure, which could allow for the injection of malicious scripts if the input is not handled carefully by the agent.
Audit Metadata