eli
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied topics through the $ARGUMENTS variable to generate HTML artifacts. This creates a surface where malicious input could attempt to influence the generated code. Ingestion points: $ARGUMENTS in SKILL.md. Boundary markers: Absent. Capability inventory: Generates HTML, CSS, and JavaScript via the Artifact tool. Sanitization: Absent.
- [DYNAMIC_EXECUTION]: The skill generates vanilla JavaScript code for interactive simulators within the artifacts. This is restricted to self-contained logic and occurs within a sandboxed environment.
- [SAFE]: No security issues such as data exfiltration, credential theft, or unauthorized command execution were found.
Audit Metadata