randroid-clean-slop

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to audit running interfaces, screenshots, and frontend code supplied by the user. This creates a surface where instructions maliciously embedded in the audited data could attempt to influence the agent's iterative design process.\n
  • Ingestion points: Interfaces, screenshots, and frontend code provided for visual audit (SKILL.md, references/rules.md).\n
  • Boundary markers: The skill provides a structured checklist of 'Slop Signs' and a specific iteration workflow which helps guide the agent's focus, but it lacks explicit instructions to ignore text-based commands within the audited content.\n
  • Capability inventory: The agent is authorized to analyze visible design problems and implement fixes to the frontend code and interaction states (SKILL.md).\n
  • Sanitization: No specific sanitization or filtering logic is provided for text content extracted from the visual or code-based audit sources.\n- [NO_CODE]: The skill does not contain any executable scripts or binary files, relying entirely on markdown instructions and YAML configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 11:21 PM
Security Audit — agent-trust-hub — randroid-clean-slop