hue

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches design assets, including CSS and fonts, from trusted and well-known providers such as Google Fonts and unpkg.com for use in generated HTML previews.
  • [SAFE]: The skill manages the risk of indirect prompt injection by providing clear defensive instructions to the agent to treat all fetched content as data rather than instructions. Ingestion point: WebFetch (SKILL.md); Boundary markers: Present (security notes explicitly instruct the AI to ignore instructions in fetched content); Capabilities: Write and Edit tools used to create generated skills; Sanitization: Focuses on extracting hex codes and stylistic facts.
  • [SAFE]: The generation of new skills in the local filesystem is the primary intended function of the tool and is performed using static templates and localized data extraction, which aligns with safe operational practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:08 PM
Security Audit — agent-trust-hub — hue