image-to-code

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection through its ingestion and implementation process.\n- Ingestion points: Data enters the agent context through user-provided website requests and text extracted from generated design images (Sections 9, 21, and 36).\n- Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the processed content.\n- Capability inventory: The agent has the capability to write frontend implementation files based on the analyzed content.\n- Sanitization: No sanitization, escaping, or validation protocols are defined for the content extracted from external or generated sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:54 PM
Security Audit — agent-trust-hub — image-to-code