design-distill
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates the
agent-browserCLI to visit user-provided URLs and execute specific JavaScript snippets viaevalto retrieve computed styles (colors, fonts, sizes). This is a core, intended functionality. - [PROMPT_INJECTION]: The instructions incorporate the 'P6' protocol, which directs the agent to 'never ask permission' when filing insights or updating internal ledgers. This grants the agent a higher degree of autonomy for background documentation tasks.
- [SAFE]: A 'Measured, not inferred' constraint is enforced, requiring the agent to use
getComputedStyleprovenance for all design data. This is a significant security and accuracy feature that prevents the agent from being influenced by potentially malicious text or deceptive visual elements on reference websites. - [SAFE]: The skill includes a self-validation step (P11) where it renders its own generated HTML specimen and captures screenshots in multiple modes to verify correctness before presenting the output to the user.
Audit Metadata