blueprinter
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided technical data to generate formatted HTML/CSS diagrams, creating a surface for potential instruction injection via data content.
- Ingestion points: User requests for architecture diagrams, system diagrams, or technical drawings (SKILL.md).
- Boundary markers: Not present.
- Capability inventory: Generation of HTML/CSS code.
- Sanitization: The instructions do not specify any sanitization or validation of user-provided labels or values before they are included in the generated output.
- [SAFE]: The skill fetches typography resources from Google Fonts to support its visual styling guidelines. This external reference targets a well-known service and is used solely for standard rendering purposes.
Audit Metadata