umbraco-ufm-component
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official documentation at docs.umbraco.com. These are legitimate resources belonging to the vendor (Umbraco) and are required for the stated task.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing markdown tokens into HTML. It mitigates this risk by documenting Umbraco's post-processing sanitizer and advising developers to escape user input as a best practice.
- [COMMAND_EXECUTION]: While the skill manifest requests the 'Write' and 'Edit' tools, these are used for the intended purpose of generating local project files and components, matching the skill's primary function.
Audit Metadata