skills/jayden-dang/skills/craft-page/Gen Agent Trust Hub

craft-page

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of instructional Markdown files (SKILL.md, TESTS.md, references/diagram.md) and a testing configuration file (eval.json). It does not include any executable scripts, binaries, or automated tasks that could perform unauthorized actions on a host system.- [EXTERNAL_DOWNLOADS]: The skill instructions contain a strong security and reliability posture by forbidding the use of external Content Delivery Networks (CDNs) for fonts or scripts. It directs the agent to inline all assets (CSS, JS, and data URIs) to ensure the generated pages are self-contained and respect Content Security Policies (CSP).- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest user requirements to produce stylized HTML. While it does not include explicit sanitization functions for user input (which is typical for a code-generation prompt), it requires a structured 'design plan' reasoning step before generating markup, which acts as a logical boundary and reduces the risk of unintended instruction following.- [SAFE]: The skill instructions promote standard, safe web development practices including accessibility (ARIA roles, keyboard focus), performance (prefers-reduced-motion), and security (offline-first, no external dependencies).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 09:38 AM
Security Audit — agent-trust-hub — craft-page