design-mirror
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its core functionality of fetching and analyzing untrusted web content.
- Ingestion points: Untrusted HTML and CSS are downloaded from external URLs via
scripts/scrape_html.shinto/tmp/target_page.htmlfor analysis. - Boundary markers: The skill instructions lack explicit delimiters or guidance for the agent to ignore natural language instructions that could be embedded in the scraped data.
- Capability inventory: The skill is capable of modifying the local filesystem, including code files and build configurations like
tailwind.config.js. - Sanitization: No sanitization is performed on the ingested content to prevent the agent from following instructions embedded within the target site's HTML or metadata.
- [COMMAND_EXECUTION]: The skill executes the scripts
scripts/screenshot.shandscripts/scrape_html.sh, which usecurlto interact with the official vendor API atapi.brightdata.com. This is expected behavior for a skill authored by the vendor to perform web scraping and screenshot tasks.
Audit Metadata