thirdparty-web-interface-guidelines

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The ATTRIBUTION.md file contains an installation command that downloads a script from the official Vercel domain and pipes it to the shell.
  • [EXTERNAL_DOWNLOADS]: The skill's update policy includes references to fetching updated instructions from the vercel-labs GitHub organization.
  • [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection because it is designed to analyze untrusted code provided by users.
  • Ingestion points: UI source code files provided for review as defined in SKILL.md.
  • Boundary markers: Absent. The skill does not instruct the agent to use specific delimiters or to disregard instructions contained within the analyzed code.
  • Capability inventory: The skill is informational and does not include local scripts with system access or network capabilities.
  • Sanitization: No sanitization or validation of the input source code is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 11:19 AM
Security Audit — agent-trust-hub — thirdparty-web-interface-guidelines