build-website
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill pos s e s s e s a n in direc t promp t i n jection surface. 1. Ingestion point s : User input is collecte d during Phase 1 Discovery (Step s 1-4) regarding busines s detail s an d copy. 2. Boun d ary marker s : No explicit delimiter s or instruction s to ignore embed d e d comman d s are use d when proces s ing this data. 3. Capability inventory : The agen t use s create_document s an d patc h_document s to write conten t, including custom HTML an d CSS, to the Sanity CMS. 4. Sanitization : No sanitization or validation of the user
- provide d string s is performe d before insertion into the CMS.
- [EXTERNAL_DOWNLOADS]: The skill include s instruction s to impor t as set s from Google Font s (font s.googleapi s.com), whic h is a well
- know n technology service. This reference is use d fo r legitimate design purpose s an d doe s no t elevate the security risk.
Audit Metadata