sn-md-to-html-report

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user-provided Markdown documents as its primary source (Ingestion Point). It lacks explicit boundary delimiters to isolate this source content from the generation instructions. While the instructions emphasize preserving factual integrity, there are no specific sanitization protocols to prevent malicious instructions or script tags within the source report from being reflected in the generated HTML and CSS (Capability: Code Generation).
  • [DYNAMIC_EXECUTION]: The skill dynamically generates HTML and CSS code at runtime based on the source report and a design plan, which is the primary intended functionality of the tool for creating stylized report pages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:17 AM
Security Audit — agent-trust-hub — sn-md-to-html-report