aria-toggle-field-name
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to analyze rendered HTML and interactive components, which constitutes an ingestion point for untrusted external data. While the skill lacks built-in capabilities for network exfiltration or file system modifications, the lack of explicit boundary markers for the ingested content means it could be susceptible to instructions embedded within the analyzed HTML.
- Ingestion points: Processes 'rendered HTML', 'interactive components', and 'markup' as described in SKILL.md.
- Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions embedded within the processed HTML.
- Capability inventory: No scripts or tools performing subprocess calls, file writes, or network operations were found in the provided files.
- Sanitization: No evidence of sanitization or filtering of the external HTML content before processing.
- [NO_CODE]: The skill consists entirely of markdown documentation and instructional content, containing no executable scripts, binaries, or automated tooling.
Audit Metadata