paste-inputs

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill references accessibility standards and technical documentation from well-known and trusted organizations, including the W3C (w3.org) and the Mozilla Developer Network (developer.mozilla.org).\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted project source code during analysis. This is a characteristic of its primary function as a code review tool.\n
  • Ingestion points: Project source code files (HTML, JavaScript) during the 'Check' and 'Code Review' steps (SKILL.md).\n
  • Boundary markers: The instructions do not specify delimiters to separate code content from agent instructions.\n
  • Capability inventory: The skill utilizes read and write capabilities to identify and remediate codebase violations.\n
  • Sanitization: No explicit sanitization or validation of the ingested code content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 12:30 AM
Security Audit — agent-trust-hub — paste-inputs