gstack-design-html
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external design descriptions and
DESIGN.mdfiles to generate code, which could contain instructions designed to manipulate the agent's output or behavior. - Ingestion points: The agent is instructed to read
DESIGN.mdand user-provided mockup descriptions in Step 0. - Capability inventory: The skill utilizes
Bash,Write, andEdittools to create and modify files and detect the project environment. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore instructions embedded within the ingested design data.
- Sanitization: The skill does not specify any sanitization or validation logic for the content processed from external design sources.
Audit Metadata