skills/broomva/skills/design-distill/Gen Agent Trust Hub

design-distill

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates the agent-browser CLI to visit user-provided URLs and execute specific JavaScript snippets via eval to retrieve computed styles (colors, fonts, sizes). This is a core, intended functionality.
  • [PROMPT_INJECTION]: The instructions incorporate the 'P6' protocol, which directs the agent to 'never ask permission' when filing insights or updating internal ledgers. This grants the agent a higher degree of autonomy for background documentation tasks.
  • [SAFE]: A 'Measured, not inferred' constraint is enforced, requiring the agent to use getComputedStyle provenance for all design data. This is a significant security and accuracy feature that prevents the agent from being influenced by potentially malicious text or deceptive visual elements on reference websites.
  • [SAFE]: The skill includes a self-validation step (P11) where it renders its own generated HTML specimen and captures screenshots in multiple modes to verify correctness before presenting the output to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:30 PM
Security Audit — agent-trust-hub — design-distill