render-html

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONOBFUSCATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an 'HTML Review Gate' where an external model (via mcp__codex__codex) audits the generated HTML against the source Markdown.
  • Ingestion points: Reads source.md and source.json artifacts from the local filesystem.
  • Boundary markers: The review prompt (in SKILL.md) instructs the model to ignore research claims and focus on fidelity, but the model is exposed to the full, untrusted content of the source files.
  • Capability inventory: The auditor's verdict (PASS/FAIL) directly influences the agent's workflow; a 'FAIL' verdict blocks the delivery of the rendered view.
  • Sanitization: While HTML tags are sanitized, the natural language content is not filtered for prompt injection instructions that might attempt to trick the auditor into passing a broken or malicious render.
  • [DATA_EXFILTRATION]: The skill transmits the full content of user artifacts (Markdown and JSON) and their absolute local file paths to a third-party model provider via the mcp__codex__codex tool for auditing purposes.
  • [PROMPT_INJECTION]: The script scripts/render_html.py uses specific Private Use Area (PUA) Unicode characters (U+E000 and U+E001) as delimiters for stashing code and math blocks during parsing. If these characters are present in user-supplied Markdown, they could be used to manipulate internal parsing state or trigger IndexError crashes during the restoration phase.
  • [OBFUSCATION]: The script scripts/render_html.py contains non-printable Unicode characters (U+2028 Line Separator and U+2029 Paragraph Separator) which are explicitly sanitized for JavaScript compatibility. While used for safety, the presence of non-standard separators often triggers steganography detection rules.
  • [COMMAND_EXECUTION]: The rendering script executes shell commands via subprocess.run to call git rev-parse --show-toplevel. This is used to resolve repository-relative paths to avoid leaking home directory structures in report metadata.
  • [EXTERNAL_DOWNLOADS]: The generated HTML reports include script and link tags that fetch MathJax and highlight.js from cdn.jsdelivr.net. These are well-known, trusted CDNs used for rendering math and syntax highlighting in the browser.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:08 PM
Security Audit — agent-trust-hub — render-html