csp-security-headers
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructions for managing security headers and Content Security Policy (CSP).
- [SAFE]: Includes references to trusted external services such as Google, Vercel, Cloudflare, and Sanity for script and asset delivery.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes external domain inputs.
- Ingestion points: Instructions in SKILL.md for adding new script, image, and iframe domains to next.config.ts.
- Boundary markers: The skill includes a checklist that cautions against using 'unsafe-inline' and 'unsafe-eval' unless strictly necessary.
- Capability inventory: The skill guides the agent to perform file-write operations on next.config.ts and src/middleware.ts.
- Sanitization: No explicit validation or filtering is specified for the external domains provided to the agent.
Audit Metadata