skills/simota/agent-skills/pixel/Gen Agent Trust Hub

pixel

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on its primary purpose of faithful design reproduction. It provides legitimate scripts for visual verification using Playwright and standard Node.js libraries, following well-established development workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests untrusted mockup images for analysis. However, it incorporates a comprehensive adversarial reasoning approach including confidence level annotations (HIGH/MEDIUM/LOW), mandatory verification loops, and structured extraction protocols that mitigate the risk of obeying hidden instructions within the image data. The capability inventory includes browser automation for screenshots, but this is scoped to local file verification. No automated exfiltration or command execution based on untrusted data was found.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources from well-known and trusted providers. It specifies the official Microsoft Playwright Docker image (mcr.microsoft.com/playwright) for consistent testing environments and links to standard technical documentation from the W3C, Mozilla Developer Network (MDN), and web.dev (Google). These references are used appropriately to guide the agent toward modern CSS standards and accessible implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — pixel