label-content-name-mismatch
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to review rendered HTML markup and interactive components provided by the user. This creates an ingestion point for untrusted data. However, the skill does not use any sensitive tools, perform file system operations, or initiate network requests, limiting the risk of exploitation to the conversational context.
- [SAFE]: The external URLs provided in the skill point to well-known and legitimate technical resources, specifically Frontend Checklist and the World Wide Web Consortium (W3C).
Audit Metadata