pixel-art-infographic-creator
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION] (LOW): The skill is vulnerable to indirect prompt injection through its toolset.
- Ingestion points: The
WebFetchtool allows the agent to ingest untrusted data from external websites. - Boundary markers: Absent; the instructions do not define delimiters or warnings to ignore instructions embedded in fetched data.
- Capability inventory: The skill possesses the
Bashtool (withpythonandnpmaccess), along withWriteandEdit, which could be exploited to execute code or modify the file system if the agent is manipulated by malicious external content. - Sanitization: Absent; no sanitization or validation of external content is mentioned.
Audit Metadata