customize-design

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCECOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is explicitly instructed to read and follow 'house rules' from a file named customize.md and user-provided 'brand guides'. The instructions state that these rules 'win over the defaults in this skill', creating a high-risk surface for indirect prompt injection where malicious instructions in these files could override the agent's safety protocols or intended behavior.
  • Ingestion points: customize.md (read via paths from pptx-gen workspace) and external 'brand guides' pointed to by the user.
  • Boundary markers: None identified. The skill is told to 'follow' the rules without mention of delimiters or filtering.
  • Capability inventory: The skill can execute shell commands (npm run, pptx-gen) and write to multiple configuration and documentation files (design.yml, design.md, customize.md).
  • Sanitization: No sanitization or validation of the instructions found in customize.md is described.
  • [PERSISTENCE]: The skill automatically writes 'recurring requests' into customize.md under a ## Rules section. Because these rules are followed in all future sessions within that workspace, this mechanism can be used to establish persistent malicious behavior if an attacker can trick the user into making a request that the agent then saves as a permanent rule.
  • [COMMAND_EXECUTION]: The skill executes several shell commands, including npm run install-fonts and pptx-gen build --script <path>. While these appear to be part of the tool's core functionality, executing scripts via npm or custom build paths provides a vector for command execution if the workspace environment or script paths are manipulated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 03:23 PM
Security Audit — agent-trust-hub — customize-design