label-content-name-mismatch

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to review rendered HTML markup and interactive components provided by the user. This creates an ingestion point for untrusted data. However, the skill does not use any sensitive tools, perform file system operations, or initiate network requests, limiting the risk of exploitation to the conversational context.
  • [SAFE]: The external URLs provided in the skill point to well-known and legitimate technical resources, specifically Frontend Checklist and the World Wide Web Consortium (W3C).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 12:30 AM
Security Audit — agent-trust-hub — label-content-name-mismatch