social-spotify-card
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's HTML template fetches the Tailwind CSS library from 'cdn.tailwindcss.com' and typography assets from Google Fonts. These are established, well-known services commonly used for web prototyping and frontend development.
- [SAFE]: The instructions explicitly forbid the use of external image links for album art, requiring the agent to generate covers using CSS gradients and geometric shapes. this implementation reduces the risk of external tracking and data leakage.
- [PROMPT_INJECTION]: The skill is designed to ingest user-supplied text (such as song titles, artist names, and playback progress) to populate a card template. While this represents a surface for indirect prompt injection, the risk is negligible as the agent's output is limited to a visual preview. Ingestion points include markdown metadata fields; boundary markers and sanitization instructions are not present but the capability inventory is limited to local rendering.
Audit Metadata