webassembly-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate developer documentation for WebAssembly. All code examples for image processing, matrix multiplication, and PI estimation are standard algorithms. The instructions emphasize security best practices such as utilizing the WASM sandbox and managing memory safely.
- [INDIRECT_PROMPT_INJECTION]: The skill includes code for processing untrusted external data, which defines an inherent attack surface for indirect prompt injection.
- Ingestion points: The
process_csvfunction inreferences/EXAMPLES.mdreads data from a user-specified file path. - Boundary markers: Not present in the provided code templates as they are low-level implementation examples.
- Capability inventory: The code demonstrates file system read/write access via the standard library (
std::fs) and WASI, and environment variable access (env::vars). - Sanitization: The examples perform simple data transformations (e.g., converting CSV content to uppercase) but do not implement specific sanitization for malicious strings within the data. This is considered acceptable for instructional examples of performance-oriented tools.
Audit Metadata