coss-particles
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides numerous links to UI component manifests hosted on the vendor domain (coss.com). These resources are intended to be fetched and processed by the agent to obtain component source code.
- [COMMAND_EXECUTION]: The file contains a command (node apps/ui/scripts/generate-particle-index.cjs) for developers to update the particle index within the project repository. This is documented as a maintenance task.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves the agent fetching and adapting source code from external JSON files, which creates a potential surface for indirect prompt injection.
- Ingestion points: 508 JSON URLs listed in the particle index (SKILL.md).
- Boundary markers: No delimiters or specific instructions are provided to the agent to treat the fetched content as data rather than instructions.
- Capability inventory: The agent is empowered to fetch, read, and adapt code for over 500 distinct UI components.
- Sanitization: The skill does not outline any validation or sanitization requirements for the content retrieved from the external manifests.
Audit Metadata