skills/pepsi1978/proggs/playground/Gen Agent Trust Hub

playground

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute the open command to launch generated HTML files in the user's default browser. This is an expected functional component of the skill's workflow for previewing interactive tools.
  • [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface as part of its core functionality. It gathers user input via interactive controls in an HTML file to construct prompts for subsequent agent tasks.
  • Ingestion points: Interactive controls and text inputs within generated HTML templates such as templates/diff-review.md and templates/document-critique.md.
  • Boundary markers: Prompts are constructed using structured templates with clear descriptive labels to delineate user-provided content from instructions.
  • Capability inventory: The agent has the capability to write local HTML files and use the open command to display them.
  • Sanitization: The JavaScript snippets in the templates use textContent for displaying the generated prompt, which mitigates script injection risks within the tool's own UI.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — playground