web-dev-explainer
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external web development code and architectural concepts, creating a potential surface for indirect prompt injection.
- Ingestion points: Code snippets and development queries provided by the user or read from project files.
- Boundary markers: The skill contains a dedicated "Anti-Patterns" section that explicitly warns the agent against treating external content, logs, or tool responses as trusted instructions.
- Capability inventory: The agent is authorized to use host-available execution tools to demonstrate code concepts (SKILL.md).
- Sanitization: The instructions require the agent to verify activation boundaries and perform safety checks before proceeding with tasks.
- [DYNAMIC_EXECUTION]: The skill allows the use of host-provided tools to demonstrate code snippets for educational purposes.
- Evidence: The prompt instructs the agent to "Use the current host's available execution tools to demonstrate code when that materially improves the explanation" (SKILL.md). This functionality is limited to demonstration within the tutor persona and is governed by the skill's internal verification protocol.
Audit Metadata