build-website

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill pos s e s s e s a n in direc t promp t i n jection surface. 1. Ingestion point s : User input is collecte d during Phase 1 Discovery (Step s 1-4) regarding busines s detail s an d copy. 2. Boun d ary marker s : No explicit delimiter s or instruction s to ignore embed d e d comman d s are use d when proces s ing this data. 3. Capability inventory : The agen t use s create_document s an d patc h_document s to write conten t, including custom HTML an d CSS, to the Sanity CMS. 4. Sanitization : No sanitization or validation of the user
  • provide d string s is performe d before insertion into the CMS.
  • [EXTERNAL_DOWNLOADS]: The skill include s instruction s to impor t as set s from Google Font s (font s.googleapi s.com), whic h is a well
  • know n technology service. This reference is use d fo r legitimate design purpose s an d doe s no t elevate the security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 12:18 AM
Security Audit — agent-trust-hub — build-website