explain-interface

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses curl and npx to fetch publicly available website content and load the Chrome DevTools MCP. These are standard operations for the skill's stated purpose of interface analysis.
  • [COMMAND_EXECUTION]: The skill provides instructions for using shell commands like curl, grep, and sed to analyze fetched HTML and CSS files. It also utilizes a scriptable browser via MCP to execute read-only JavaScript snippets for inspecting the DOM.
  • [SAFE]: All JavaScript snippets provided for evaluate_script are read-only inspection tools (e.g., getComputedStyle, document.querySelectorAll, performance.getEntriesByType). They collect layout and styling data without modifying the page or exfiltrating sensitive local data.
  • [SAFE]: The skill includes explicit warnings against executing imperative text found in page content, treating it as evidence rather than instruction, which mitigates indirect prompt injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 12:05 AM
Security Audit — agent-trust-hub — explain-interface