favicon
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized commands were detected. The skill consists of instructional markdown and code snippets for web development.
- [EXTERNAL_DOWNLOADS]: Links in the skill point to reputable developer documentation from Google and Frontend Checklist for informational purposes. These references are safe and do not facilitate automated downloads or remote code execution.
- [SAFE]: An indirect prompt injection surface is present in the auditing instructions. 1. Ingestion points: The skill instructs agents to read and analyze HTML
<head>tags from external websites (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: None; the skill provides diagnostic instructions only and does not include executable tools, file-write permissions, or shell access. 4. Sanitization: Absent. The risk is negligible as the skill lacks exploitable capabilities.
Audit Metadata