cross-device-check

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its requirement to process untrusted project data and source code to perform UI audits.
  • Ingestion points: The skill reads project configuration, distribution targets, and engine/runtime settings (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the analyzed project files.
  • Capability inventory: The skill is authorized to report defects and apply fixes to the project source code upon user approval (SKILL.md).
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the ingested project data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 10:36 AM
Security Audit — agent-trust-hub — cross-device-check