tiny-robot-skill
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the development of chat interfaces that process untrusted data from AI responses, creating a surface for potential indirect prompt injection attacks.
- Ingestion points: Untrusted content enters the agent's context via components such as
tr-bubbleandtr-bubble-listas demonstrated indemos/bubble/markdown.vueanddemos/bubble/list.vue. - Boundary markers: The skill does not explicitly provide instructions or patterns for using boundary markers to isolate untrusted data, relying on standard rendering flow.
- Capability inventory: The framework supports rendering complex content types including Markdown and custom WebComponents (e.g.,
schema-cardindemos/bubble/schema-render.vue), which could be leveraged to display deceptive or malicious UI if the source data is compromised. - Sanitization: Integration examples (such as
demos/bubble/schema-render.vue) correctly utilizedompurifyto sanitize HTML content, which serves as a mitigation for common injection-based attacks.
Audit Metadata