blocked-links

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted external data in the form of HTML and JavaScript source code, which represents an indirect prompt injection attack surface.
  • Ingestion points: The agent ingests and processes HTML source and JavaScript files provided as input for review.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the analyzed source code.
  • Capability inventory: The skill uses the agent's analytical and reporting capabilities; it does not define or require the use of file system writes, network requests, or shell execution tools.
  • Sanitization: No sanitization or escaping procedures are specified for the external content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:29 AM
Security Audit — agent-trust-hub — blocked-links