duplicate-id-active
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to review and analyze rendered HTML code and design-system patterns, which introduces a potential surface for indirect prompt injection. \n
- Ingestion points: User-provided HTML markup and interactive components described in SKILL.md and references/rule.md. \n
- Boundary markers: Absent; the instructions do not specify delimiters or protective wrappers for the external code being reviewed. \n
- Capability inventory: No scripts, executables, or tool configurations are provided in the skill files; the agent relies on its inherent capabilities. \n
- Sanitization: Absent; there are no instructions to validate or sanitize the ingested HTML content. \n- [NO_CODE]: The skill is composed exclusively of Markdown documentation and reference materials; it does not include any scripts, configuration files for package managers, or executable binaries.
Audit Metadata