pencil-design-from-stitch-html

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external HTML data fetched from Stitch URLs or provided directly by users to generate Pencil design operations. This creates an attack surface for indirect prompt injection, where malicious instructions hidden in the source HTML (e.g., in metadata or hidden elements) could attempt to influence the agent's behavior during the conversion process. While the skill follows structured mapping rules, it lacks explicit sanitization or boundary markers to isolate instructions that might be embedded in the untrusted input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:04 PM
Security Audit — agent-trust-hub — pencil-design-from-stitch-html