favicons
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process untrusted data (HTML and templates) to perform code reviews, creating an indirect prompt injection surface. * Ingestion points: The 'Code Review' section in SKILL.md instructs the agent to review templates and rendered HTML. * Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are provided in the instructions. * Capability inventory: The skill involves analyzing and flagging HTML elements. No automated shell execution or network exfiltration is configured for the agent within the skill's own operational context. * Sanitization: No sanitization or filtering of the external content is performed before processing.
Audit Metadata