instagram

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting untrusted creative data and interpolating it into HTML mockups that are automatically rendered.
  • Ingestion points: Creative Direction, Creative Brief, Target Segment, and Brand Guidelines are ingested from the agent context (SKILL.md).
  • Boundary markers: The instructions do not define boundary markers or "ignore instructions" warnings for the ingested data.
  • Capability inventory: The skill has the capability to write HTML files to the local file system and programmatically open them using the mcp__tdx-studio__open_file tool (SKILL.md).
  • Sanitization: There is no evidence of sanitization or escaping of the ingested data before it is inserted into the HTML templates, which could allow arbitrary content rendering in the preview.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:59 AM
Security Audit — agent-trust-hub — instagram