user-activation-contracts
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes user-provided technical scenarios and failure logs regarding browser API behaviors. This processing of untrusted external content represents a surface for indirect prompt injection.\n
- Ingestion points: User descriptions of code execution sequences and browser interaction logs provided during analysis.\n
- Boundary markers: The instructions do not define specific delimiters or directives to ignore instructions embedded within the analyzed data.\n
- Capability inventory: The skill is primarily instructional and diagnostic; it does not explicitly define tools for file system access, network exfiltration, or command execution.\n
- Sanitization: No explicit sanitization or validation of the ingested input data is described.\n- [EXTERNAL_DOWNLOADS]: The skill references official documentation and technical issue trackers from established sources including Mozilla, WHATWG, and GitHub. These links are provided for educational and technical reference purposes.
Audit Metadata