tiny-robot-skill

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the development of chat interfaces that process untrusted data from AI responses, creating a surface for potential indirect prompt injection attacks.
  • Ingestion points: Untrusted content enters the agent's context via components such as tr-bubble and tr-bubble-list as demonstrated in demos/bubble/markdown.vue and demos/bubble/list.vue.
  • Boundary markers: The skill does not explicitly provide instructions or patterns for using boundary markers to isolate untrusted data, relying on standard rendering flow.
  • Capability inventory: The framework supports rendering complex content types including Markdown and custom WebComponents (e.g., schema-card in demos/bubble/schema-render.vue), which could be leveraged to display deceptive or malicious UI if the source data is compromised.
  • Sanitization: Integration examples (such as demos/bubble/schema-render.vue) correctly utilize dompurify to sanitize HTML content, which serves as a mitigation for common injection-based attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:26 AM
Security Audit — agent-trust-hub — tiny-robot-skill