web-prototype

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No remote code execution or external network operations were detected. All assets are local to the skill package.- [SAFE]: The skill instructions explicitly forbid external URLs for images, which mitigates potential data leakage or tracking via remote assets.- [SAFE]: No sensitive file access or credential exposure patterns were found. Placeholders used in templates are benign.- [SAFE]: While the skill ingests user input to populate HTML templates (Indirect Prompt Injection surface), it operates within a constrained static context and does not provide an execution path for malicious payloads beyond the generated artifact itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 02:09 AM