dashboard-creator
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill extracts metrics, titles, and labels from user requests and interpolates them directly into HTML templates (e.g.,
assets/templates/base_template.htmlandSKILL.mdpatterns) without sanitization. If an attacker provides data containing malicious HTML or JavaScript, it will be written directly into the output file. - Ingestion points: Metric values, labels, and dashboard names extracted from the user's primary prompt as described in the
SKILL.mdworkflow. - Boundary markers: Absent. There are no instructions to use delimiters or ignore embedded control characters within the extracted data.
- Capability inventory: The skill uses file-system tools to write to local HTML files (e.g.,
[name]-dashboard.html). - Sanitization: Absent. The instructions do not include steps to escape HTML characters or validate the extracted metrics before generation.
Audit Metadata