surprise-me
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill represents an indirect prompt injection surface as it aggregates instructions from other skills and external news information. Ingestion points: SKILL.md files in the available_skills context and news search results. Boundary markers: Absent; the skill does not define delimiters to isolate instructions from different sources. Capability inventory: following instructions from other skills and generating interactive HTML/React artifacts. Sanitization: Absent; no validation is performed on instructions ingested from external skills or search data.
- [COMMAND_EXECUTION]: The skill may dynamically generate interactive web content, such as HTML/React mini-games or generative art, which involves the creation of executable code for creative presentation purposes.
Audit Metadata