embedded-or-inline-css

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's primary intent is educational, providing frontend development best practices and code examples. No malicious code, obfuscation, unauthorized data exfiltration, or privilege escalation patterns were detected within the documentation or example scripts.\n- [PROMPT_INJECTION]: The skill facilitates the analysis of user-provided source code (HTML, CSS, and component files), which constitutes a surface for indirect prompt injection. Malicious instructions could be embedded in the reviewed code to attempt to influence the agent's behavior.\n
  • Ingestion points: Source code, including HTML templates, stylesheets, and component files provided by the user for review in SKILL.md and references/rule.md.\n
  • Boundary markers: Absent. The instructions do not provide explicit delimiters or warnings to the agent to disregard instructions contained within the analyzed content.\n
  • Capability inventory: The agent has the capability to read project files and generate code proposals based on its analysis.\n
  • Sanitization: Absent. The skill does not prescribe any sanitization or validation steps for the user-provided files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:29 AM
Security Audit — agent-trust-hub — embedded-or-inline-css