plugin-heavy-dep
Warn
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructs the agent to implement dynamic loading of JavaScript modules using
import()from computed paths served via custom host routes. This pattern facilitates the loading and execution of code chunks at runtime based on application logic. - [INDIRECT_PROMPT_INJECTION]: The skill describes a vulnerability surface where untrusted markup generated by external dependencies is rendered in the Web UI, potentially allowing for indirect prompt injection if payloads are not properly handled. Evidence chain for this surface:
- Ingestion points: The renderer (e.g., Mermaid) processes untrusted markdown or model-generated text to produce SVG/HTML output (Section 5).
- Boundary markers: The skill does not mention specific prompt-level boundary markers, but focuses on post-processing technical controls.
- Capability inventory: The integrated dependencies have the capability to render complex markup to the DOM, often using
innerHTMLor similar patterns (Section 5). - Sanitization: The skill explicitly mandates a zero-dependency whitelist sanitization pass to strip hazardous elements and attributes, including
scripttags,foreignObjectcontainers,on*event handlers, and allhref/xlink:hreflinks (Section 5).
Audit Metadata