csp-security-headers

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructions for managing security headers and Content Security Policy (CSP).
  • [SAFE]: Includes references to trusted external services such as Google, Vercel, Cloudflare, and Sanity for script and asset delivery.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes external domain inputs.
  • Ingestion points: Instructions in SKILL.md for adding new script, image, and iframe domains to next.config.ts.
  • Boundary markers: The skill includes a checklist that cautions against using 'unsafe-inline' and 'unsafe-eval' unless strictly necessary.
  • Capability inventory: The skill guides the agent to perform file-write operations on next.config.ts and src/middleware.ts.
  • Sanitization: No explicit validation or filtering is specified for the external domains provided to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:18 PM
Security Audit — agent-trust-hub — csp-security-headers