skills/rheinmir/setup/hallmark/Gen Agent Trust Hub

hallmark

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script located at harness/scripts/design-variety.py to maintain a log of design choices and ensure structural variety across different page builds.
  • [EXTERNAL_DOWNLOADS]: The hallmark study verb utilizes the WebFetch tool to retrieve HTML and CSS data from external URLs. This process includes explicit security checks to prevent access to local network resources, internal hostnames, and private IP address ranges.
  • [PROMPT_INJECTION]: The skill processes untrusted data from third-party websites during design extraction. The instructions in references/study.md provide proactive defenses by directing the agent to treat all fetched content as inert data and to disregard any embedded instructions that attempt to override system protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 03:08 PM
Security Audit — agent-trust-hub — hallmark