NYC

create-an-asset

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • Indirect Prompt Injection (LOW): The skill processes untrusted data from prospect websites and user-uploaded transcripts to generate HTML assets. This creates a surface where embedded instructions in those sources could hijack the output. 1. Ingestion points: Prospect websites (via research) and uploaded call recordings/transcripts. 2. Boundary markers: No delimiters or warnings for the agent to ignore instructions within the data are present. 3. Capability inventory: The skill can search the web and write complex HTML files. 4. Sanitization: No explicit filtering or validation of external content is defined.
  • No Code (SAFE): No executable scripts, binary files, or dependency manifests were found in the provided files. The skill relies entirely on high-level instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:11 PM