nuke-design
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references a large volume of external design resources, technical blogs, and documentation (e.g., Awwwards, NN/g, Linear's design docs, CSS-Tricks). These are provided as legitimate educational and reference material for the skill's purpose. Included in these references are official resources from Anthropic and well-known technology organizations, which are documented neutrally.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to process external URLs and screenshots provided by users for design review. While the skill lacks explicit boundary markers or sanitization instructions for instructions that might be embedded in target visual data, this is a common characteristic of analysis skills and represents a low-level structural risk rather than a specific vulnerability.
- [COMMAND_EXECUTION]: The skill documentation refers to a broader pipeline of tools including an executor tier (nuke-exec). These references describe the operational context within a multi-skill environment and do not constitute unsafe command execution within the scope of this skill's logic.
Audit Metadata