render-html
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONOBFUSCATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements an 'HTML Review Gate' where an external model (via
mcp__codex__codex) audits the generated HTML against the source Markdown. - Ingestion points: Reads
source.mdandsource.jsonartifacts from the local filesystem. - Boundary markers: The review prompt (in
SKILL.md) instructs the model to ignore research claims and focus on fidelity, but the model is exposed to the full, untrusted content of the source files. - Capability inventory: The auditor's verdict (PASS/FAIL) directly influences the agent's workflow; a 'FAIL' verdict blocks the delivery of the rendered view.
- Sanitization: While HTML tags are sanitized, the natural language content is not filtered for prompt injection instructions that might attempt to trick the auditor into passing a broken or malicious render.
- [DATA_EXFILTRATION]: The skill transmits the full content of user artifacts (Markdown and JSON) and their absolute local file paths to a third-party model provider via the
mcp__codex__codextool for auditing purposes. - [PROMPT_INJECTION]: The script
scripts/render_html.pyuses specific Private Use Area (PUA) Unicode characters (U+E000andU+E001) as delimiters for stashing code and math blocks during parsing. If these characters are present in user-supplied Markdown, they could be used to manipulate internal parsing state or triggerIndexErrorcrashes during the restoration phase. - [OBFUSCATION]: The script
scripts/render_html.pycontains non-printable Unicode characters (U+2028 Line Separator and U+2029 Paragraph Separator) which are explicitly sanitized for JavaScript compatibility. While used for safety, the presence of non-standard separators often triggers steganography detection rules. - [COMMAND_EXECUTION]: The rendering script executes shell commands via
subprocess.runto callgit rev-parse --show-toplevel. This is used to resolve repository-relative paths to avoid leaking home directory structures in report metadata. - [EXTERNAL_DOWNLOADS]: The generated HTML reports include script and link tags that fetch
MathJaxandhighlight.jsfromcdn.jsdelivr.net. These are well-known, trusted CDNs used for rendering math and syntax highlighting in the browser.
Audit Metadata