cover-letter

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses .textContent to render user-provided data in assets/webview.html. This is a security best practice that prevents Cross-Site Scripting (XSS) by ensuring user input is treated as literal text rather than executable HTML.
  • [PROMPT_INJECTION]: No malicious instructions, bypass attempts, or system prompt extraction patterns were found in the instructions or metadata.
  • [DATA_EXFILTRATION]: The skill does not perform any network operations or access sensitive file paths. Data remains local to the generated webview URL.
  • [COMMAND_EXECUTION]: The skill does not execute shell commands or use risky system functions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 08:22 AM
Security Audit — agent-trust-hub — cover-letter