frontend-planning-html

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates within a restricted local workspace and generates static web assets. It does not engage in network activity, credential harvesting, or privilege escalation.
  • [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection by processing external configuration files to guide code generation. (1) Ingestion points: .docs/planning/frontend/brief.md and .docs/planning/frontend/sitemap.json. (2) Boundary markers: None identified in the workflow instructions. (3) Capability inventory: File system write access to create HTML, CSS, and JS prototype files in the .docs/planning/frontend/concepts/ directory. (4) Sanitization: None identified for the ingested file content. The risk is evaluated as safe because the skill is limited to generating static code files and lacks the ability to execute arbitrary commands or perform network exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 01:44 PM
Security Audit — agent-trust-hub — frontend-planning-html