web-technique-to-skill

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not perform any dangerous operations.
  • [NO_CODE]: The skill consists of markdown documentation and a static HTML/JavaScript demo. The demo is self-contained, runs in the browser, and does not require external libraries, network access, or host-level execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for analyzing external source code to extract design mechanisms, creating an ingestion surface for untrusted data. 1. Ingestion points: User-provided source code (HTML/JS/CSS) for the extraction process. 2. Boundary markers: The skill instructs the use of a structured triage table and mechanism definition to isolate components. 3. Capability inventory: The instructions involve the agent writing documentation and skill files; there is no instruction to execute the ingested code. 4. Sanitization: No explicit sanitization of input code is defined, but the process is restricted to analytical extraction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:30 AM
Security Audit — agent-trust-hub — web-technique-to-skill