algorithmic-art
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The instructions mandate the agent to project a highly expert persona by repeatedly using specific phrases regarding craftsmanship and implementation quality (e.g., 'meticulously crafted', 'deep expertise'). This shapes the agent's descriptive behavior to emphasize quality and effort.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user requests to generate code-based art, which is then rendered as an interactive HTML artifact. This creates a surface where malicious user input could potentially be interpolated into the generated JavaScript code.
- Ingestion points: Interprets 'user request' from SKILL.md to derive conceptual seeds and algorithmic implementation details.
- Boundary markers: No explicit delimiters or 'ignore' instructions are provided to separate user-provided concepts from the generated code logic.
- Capability inventory: The system generates standalone HTML/JS files using templates/viewer.html, allowing full browser-based code execution.
- Sanitization: There is no requirement for sanitizing or validating user-supplied creative concepts before they are processed into the final code artifact.
- [EXTERNAL_DOWNLOADS]: The skill's viewer template fetches the p5.js library from Cloudflare's public CDNJS repository at 'https://cdnjs.cloudflare.com/ajax/libs/p5.js/1.7.0/p5.min.js'. This is a neutral reference to a well-known service for hosting established open-source libraries.
Audit Metadata