lp-speed
Warn
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains deceptive metadata. The 'author' field in the frontmatter is set to '10x Team', which is inconsistent with the authoritative author context 'OpenAnalystInc' provided for this skill. This discrepancy can mislead users regarding the origin and trustworthiness of the skill.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted code from user-provided HTML, CSS, and JavaScript files while having the capability to modify the filesystem via 'write', 'edit', and 'bash' tools.
- Ingestion points: As described in Step 1, the agent is instructed to read all project resources using tools like 'read', 'glob', and 'grep'.
- Boundary markers: The instructions fail to define delimiters or safety constraints to prevent the agent from executing instructions potentially hidden within the code it analyzes.
- Capability inventory: The skill is granted powerful tools including 'write', 'edit', and 'bash', allowing for broad environmental changes.
- Sanitization: No data validation or sanitization is required for the content processed from external files.
Audit Metadata