road-trip-planner

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for itinerary planning and guide generation. It does not exhibit malicious patterns, credential harvesting, or unauthorized access to sensitive data.
  • [EXTERNAL_DOWNLOADS]: The skill's HTML template fetches resources from well-known technology services, including Google Fonts, CARTO for map tiles, and the Leaflet.js library via the Cloudflare CDN. These references are essential for the interactive map and styling features described in the skill's purpose.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it ingests data from external web searches (weather, attraction details, hours) and interpolates it into generated files. 1. Ingestion points: web_search tool output in SKILL.md steps 3, 4, and 5. 2. Boundary markers: Absent. 3. Capability inventory: File-write operations to the output directory as defined in SKILL.md. 4. Sanitization: Absent. The risk is considered minimal as the ingested data is limited to travel-related information and processed into fixed templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 02:02 AM