email-design
Fail
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses
npxto install a third-party package (belt-sh/cli) and utilizes thebelt app runcommand to execute remote logic for HTML-to-image conversion and AI image generation. - [EXTERNAL_DOWNLOADS]: The skill fetches content and installation guidelines from an external GitHub repository (
inference-sh/skills). - [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by passing user-influenced HTML strings directly into remote rendering tools without visible sanitization or boundary markers.
Recommendations
- AI detected serious security threats
Audit Metadata