html-to-bricks

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches HTML and CSS content from external URLs provided by the user to facilitate design migration.- [DATA_EXFILTRATION]: Records usage telemetry including element counts, software versions, and duration, which is sent to the vendor's API at https://www.respira.press/api/skills/track-usage.- [PROMPT_INJECTION]: Ingests untrusted HTML and CSS data from conversation history, external URLs, and local files (Step 4). While this represents an indirect prompt injection surface, the risk is mitigated by the structural mapping process which converts data into Bricks element schemas rather than performing raw execution or injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 01:48 PM
Security Audit — agent-trust-hub — html-to-bricks