huashu-design

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using npx playwright screenshot to capture images of dynamically generated HTML files. This is a controlled use of a standard tool for visual rendering.
  • [DYNAMIC_EXECUTION]: The workflow involves generating HTML and CSS files based on user requirements and then executing a browser-based tool to render them. This script generation and execution pattern is a core part of the skill's design prototyping functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user content (themes and text) to populate its design demos, creating a surface for indirect prompt injection.
  • Ingestion points: User input provided during the requirement gathering phase (Phase 1).
  • Boundary markers: Absent; there are no specific instructions or delimiters to isolate user content from the agent's instructions.
  • Capability inventory: The skill can write files to the _temp/design-demos/ directory, execute npx playwright shell commands, and invoke the nano-banana-pro image generation tool.
  • Sanitization: No sanitization or validation of user-provided content is mentioned before it is interpolated into the HTML templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — huashu-design