html-to-interaction-prompts

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to utilize git for version control and ffprobe for validating the integrity of recorded MP4 videos. It also describes a workflow for serving HTML content on localhost to facilitate rendering and screenshot capture in isolated environments.\n- [EXTERNAL_DOWNLOADS]: The agent is instructed to fetch content from live external URLs, including Framer marketplace previews and other live websites, to capture visual evidence and record motion behavior for inclusion in articles.\n- [PROMPT_INJECTION]: The skill analyzes untrusted HTML, CSS, and Javascript files, creating a surface for potential indirect prompt injection attacks.\n
  • Ingestion points: Source code provided via local HTML files or remote URLs during the interaction extraction process.\n
  • Boundary markers: Absent; there are no specific instructions for the agent to distinguish between data and instructions when analyzing source code.\n
  • Capability inventory: File system write access for generating markdown and media assets, git version control commands, and shell-based media verification.\n
  • Sanitization: Absent; no filtering or validation requirements are defined for the source code ingested by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 06:56 PM
Security Audit — agent-trust-hub — html-to-interaction-prompts