duplicate-id-active

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to review and analyze rendered HTML code and design-system patterns, which introduces a potential surface for indirect prompt injection. \n
  • Ingestion points: User-provided HTML markup and interactive components described in SKILL.md and references/rule.md. \n
  • Boundary markers: Absent; the instructions do not specify delimiters or protective wrappers for the external code being reviewed. \n
  • Capability inventory: No scripts, executables, or tool configurations are provided in the skill files; the agent relies on its inherent capabilities. \n
  • Sanitization: Absent; there are no instructions to validate or sanitize the ingested HTML content. \n- [NO_CODE]: The skill is composed exclusively of Markdown documentation and reference materials; it does not include any scripts, configuration files for package managers, or executable binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 05:58 PM
Security Audit — agent-trust-hub — duplicate-id-active