customize-design
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is explicitly instructed to read and follow 'house rules' from a file named
customize.mdand user-provided 'brand guides'. The instructions state that these rules 'win over the defaults in this skill', creating a high-risk surface for indirect prompt injection where malicious instructions in these files could override the agent's safety protocols or intended behavior. - Ingestion points:
customize.md(read via paths frompptx-gen workspace) and external 'brand guides' pointed to by the user. - Boundary markers: None identified. The skill is told to 'follow' the rules without mention of delimiters or filtering.
- Capability inventory: The skill can execute shell commands (
npm run,pptx-gen) and write to multiple configuration and documentation files (design.yml,design.md,customize.md). - Sanitization: No sanitization or validation of the instructions found in
customize.mdis described. - [PERSISTENCE]: The skill automatically writes 'recurring requests' into
customize.mdunder a## Rulessection. Because these rules are followed in all future sessions within that workspace, this mechanism can be used to establish persistent malicious behavior if an attacker can trick the user into making a request that the agent then saves as a permanent rule. - [COMMAND_EXECUTION]: The skill executes several shell commands, including
npm run install-fontsandpptx-gen build --script <path>. While these appear to be part of the tool's core functionality, executing scripts vianpmor custom build paths provides a vector for command execution if the workspace environment or script paths are manipulated.
Audit Metadata