preline-mcp

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user input to modify local files. 1. Ingestion points: User prompts requesting UI components or page layouts in SKILL.md. 2. Boundary markers: None identified. The instructions do not define clear boundaries or 'ignore' commands for the user-provided data. 3. Capability inventory: The skill has the capability to read and write local HTML files and execute external MCP tools as defined in mcp-tools-reference.md. 4. Sanitization: The skill relies on natural language instructions for the agent to 'change text only' during integration, which does not provide robust technical sanitization of user-provided content.
  • [EXTERNAL_DOWNLOADS]: The skill integrates external resources by inserting script tags for Preline core components and third-party libraries (e.g., lodash, apexcharts) into the target HTML file, following the placement logic defined in the Integration Rules of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 03:42 AM
Security Audit — agent-trust-hub — preline-mcp