thirdparty-web-interface-guidelines
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
ATTRIBUTION.mdfile contains an installation command that downloads a script from the official Vercel domain and pipes it to the shell. - [EXTERNAL_DOWNLOADS]: The skill's update policy includes references to fetching updated instructions from the
vercel-labsGitHub organization. - [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection because it is designed to analyze untrusted code provided by users.
- Ingestion points: UI source code files provided for review as defined in
SKILL.md. - Boundary markers: Absent. The skill does not instruct the agent to use specific delimiters or to disregard instructions contained within the analyzed code.
- Capability inventory: The skill is informational and does not include local scripts with system access or network capabilities.
- Sanitization: No sanitization or validation of the input source code is described.
Audit Metadata