pm-experiment-designer

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to the unsanitized interpolation of untrusted user data into the final HTML output.\n
  • Ingestion points: User-provided experiment details, goals, and metric definitions serve as untrusted data sources ingested through natural language prompts.\n
  • Boundary markers: The skill lacks explicit delimiters or instructions for the agent to distinguish between user data and its own internal instructions during processing.\n
  • Capability inventory: The skill is designed to generate a single-file HTML document (assets/experiment-template.html) that includes embedded CSS and functional JavaScript (e.g., a sample size calculator).\n
  • Sanitization: There are no instructions or mechanisms defined in the skill to escape or sanitize the interpolated user content, which could allow malicious scripts or formatting to be injected into the generated HTML report if a user provides specially crafted input.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:38 AM
Security Audit — agent-trust-hub — pm-experiment-designer