graphic-design

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate design guidance and templates without any detected malicious patterns or harmful code execution.
  • [EXTERNAL_DOWNLOADS]: The skill generates HTML code that references Google Fonts (fonts.googleapis.com), which is a well-known and standard service for web typography.
  • [PROMPT_INJECTION]: The skill utilizes a surface for indirect prompt injection as it processes design briefs and local configuration for generation tasks.
  • Ingestion points: Design briefs provided by the user and local design-context files (SKILL.md).
  • Boundary markers: None explicitly defined for isolating user-supplied content within the prompt templates.
  • Capability inventory: AI image generation (Gemini) and production of production-ready HTML/CSS code.
  • Sanitization: The skill does not define specific validation or filtering mechanisms for ingested data prior to its use in prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 07:37 PM
Security Audit — agent-trust-hub — graphic-design