appllama-design-skill
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data, such as real-world screen references and AI-generated image assets, which creates a surface where malicious instructions could be embedded in the processed content.
- Ingestion points: Screen references retrieved via external MCP tools (Appllama MCP) and assets generated by image models.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands to isolate processed design data from the agent's instruction context.
- Capability inventory: The skill can generate source code, execute simulator-related shell commands (simctl), and interact with external API tools.
- Sanitization: There is no mention of validating or sanitizing the content of external design references before processing.
Audit Metadata