blocked-links
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted external data in the form of HTML and JavaScript source code, which represents an indirect prompt injection attack surface.
- Ingestion points: The agent ingests and processes HTML source and JavaScript files provided as input for review.
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the analyzed source code.
- Capability inventory: The skill uses the agent's analytical and reporting capabilities; it does not define or require the use of file system writes, network requests, or shell execution tools.
- Sanitization: No sanitization or escaping procedures are specified for the external content before processing.
Audit Metadata