quick-view
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest structured data, drafts, and content from external sources (e.g., social media citations) and render it in a browser. It lacks explicit instructions to sanitize or escape HTML entities in the
{content}placeholder, which creates a Cross-Site Scripting (XSS) vulnerability surface if the ingested data contains malicious scripts. - Ingestion points: Data identified from files, variables, or recent output (e.g.,
_private/drafts/outreach_drafts.md). - Boundary markers: Absent.
- Capability inventory: File writing, file renaming (
mv), and shell command execution (open). - Sanitization: Absent.
- [DYNAMIC_EXECUTION]: The skill generates HTML files that include JavaScript logic for UI features like truncation toggles, clipboard copying, and local storage management at runtime.
- Evidence: The
assets/base-template.htmlandreferences/full-guide.mdfiles provide script blocks that the agent is instructed to include in the generated output files. - [COMMAND_EXECUTION]: The skill uses the
opencommand to launch the generated HTML files in the user's default web browser. - Evidence:
SKILL.mdcontains the instruction: "Open withopen _private/views/{filename}."
Audit Metadata