design-mirror

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its core functionality of fetching and analyzing untrusted web content.
  • Ingestion points: Untrusted HTML and CSS are downloaded from external URLs via scripts/scrape_html.sh into /tmp/target_page.html for analysis.
  • Boundary markers: The skill instructions lack explicit delimiters or guidance for the agent to ignore natural language instructions that could be embedded in the scraped data.
  • Capability inventory: The skill is capable of modifying the local filesystem, including code files and build configurations like tailwind.config.js.
  • Sanitization: No sanitization is performed on the ingested content to prevent the agent from following instructions embedded within the target site's HTML or metadata.
  • [COMMAND_EXECUTION]: The skill executes the scripts scripts/screenshot.sh and scripts/scrape_html.sh, which use curl to interact with the official vendor API at api.brightdata.com. This is expected behavior for a skill authored by the vendor to perform web scraping and screenshot tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:45 PM
Security Audit — agent-trust-hub — design-mirror