md-section

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and transform arbitrary HTML layouts provided by users. This input surface could theoretically be used for indirect prompt injection; however, the skill explicitly instructs the agent to strip all <script> tags, external stylesheets, and dangerous HTML attributes like onclick, onerror, src, and href. These sanitization steps are designed to prevent the generation of malicious payloads.
  • [SAFE]: No evidence of data exfiltration, command execution, or unauthorized network activity was found. The skill does not use obfuscation techniques or external dependencies that would compromise the host environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:58 PM
Security Audit — agent-trust-hub — md-section