html-playground

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructions mandate that the agent generate a self-contained HTML file (including CSS and JavaScript) and subsequently execute that code by opening it in a desktop browser to verify interactive functionality. This involves the generation and execution of code based on user-provided requirements and predefined templates.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and visualize external data such as code diffs, architecture maps, and document contents. Because the agent is instructed to interact with every control and verify outputs, malicious instructions embedded within the data (e.g., in a code comment within a diff or a document being critiqued) could attempt to override the agent's behavior during the interaction phase.\n
  • Ingestion points: External requirements for playground generation, document content (templates/document-critique.md), and codebase diffs (templates/diff-review.md).\n
  • Boundary markers: The generated HTML artifacts do not include explicit security boundaries or instructions to the agent to ignore content within the data fields.\n
  • Capability inventory: File system write access and browser-based tool interaction.\n
  • Sanitization: Templates demonstrate basic string replacement for UI rendering but lack comprehensive sanitization logic to prevent the interpolation of malicious scripts or prompt instructions into the generated interactive tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:06 PM