preline-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user input to modify local files. 1. Ingestion points: User prompts requesting UI components or page layouts in SKILL.md. 2. Boundary markers: None identified. The instructions do not define clear boundaries or 'ignore' commands for the user-provided data. 3. Capability inventory: The skill has the capability to read and write local HTML files and execute external MCP tools as defined in mcp-tools-reference.md. 4. Sanitization: The skill relies on natural language instructions for the agent to 'change text only' during integration, which does not provide robust technical sanitization of user-provided content.
- [EXTERNAL_DOWNLOADS]: The skill integrates external resources by inserting script tags for Preline core components and third-party libraries (e.g., lodash, apexcharts) into the target HTML file, following the placement logic defined in the Integration Rules of SKILL.md.
Audit Metadata