ui-security-sandbox

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive security guidelines for hardening agent-rendered user interfaces.
  • [SAFE]: It contains defensive recommendations for authoring Content Security Policies (CSP), including connectDomains and resourceDomains, to prevent unauthorized data exfiltration.
  • [SAFE]: All code snippets demonstrating unsafe practices (e.g., innerHTML, eval, javascript: URLs) are explicitly marked as dangerous and accompanied by secure alternatives.
  • [SAFE]: The instructions emphasize the use of app.openLink for host-mediated navigation to prevent malicious URL redirections.
  • [SAFE]: The content includes guidance on identifying and mitigating indirect prompt injection by advising developers to pass structured facts rather than raw third-party text to model context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 10:14 AM
Security Audit — agent-trust-hub — ui-security-sandbox