aria-toggle-field-name

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to analyze rendered HTML and interactive components, which constitutes an ingestion point for untrusted external data. While the skill lacks built-in capabilities for network exfiltration or file system modifications, the lack of explicit boundary markers for the ingested content means it could be susceptible to instructions embedded within the analyzed HTML.
  • Ingestion points: Processes 'rendered HTML', 'interactive components', and 'markup' as described in SKILL.md.
  • Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions embedded within the processed HTML.
  • Capability inventory: No scripts or tools performing subprocess calls, file writes, or network operations were found in the provided files.
  • Sanitization: No evidence of sanitization or filtering of the external HTML content before processing.
  • [NO_CODE]: The skill consists entirely of markdown documentation and instructional content, containing no executable scripts, binaries, or automated tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 05:58 PM
Security Audit — agent-trust-hub — aria-toggle-field-name