html-to-interaction-prompts

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted HTML, CSS, and JavaScript from local files or live websites (SKILL.md), creating a surface for indirect prompt injection. \n
  • Ingestion points: HTML, CSS, and script files provided by the user or fetched from URLs. \n
  • Boundary markers: The instructions do not specify explicit delimiters or warnings to ignore instructions found within the analyzed source code. \n
  • Capability inventory: The agent is authorized to write files, capture screenshots/video, use ffprobe, and perform git operations. \n
  • Sanitization: The skill does not define methods for sanitizing or escaping content read from external HTML sources before processing. \n- [COMMAND_EXECUTION]: The workflow includes the use of local system commands, specifically git for staging and committing article assets, and ffprobe for verifying the readability and contents of recorded MP4 files (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:37 PM
Security Audit — agent-trust-hub — html-to-interaction-prompts