interaction-designer
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The SKILL.md file uses dynamic context injection (!command) to execute cat commands on local protocol and configuration files. This hydration process allows the agent to load project-specific design rules from ux-protocol.md, design-mindset-and-rules.md, and .production-grade.yaml.
- [COMMAND_EXECUTION]: The LITE.md file instructs the agent to execute diagnostic shell commands (find, cat, jq, ls) to discover project dependencies and documentation structures within the local filesystem.
- [PROMPT_INJECTION]: The skill contains a potential surface for indirect prompt injection as it processes project-level files to generate UI components and specifications. Evidence Chain: Ingestion points include .production-grade.yaml, package.json, and the docs/ directory; no boundary markers or sanitization are specified; the agent has the capability to write React components to src/components/.
Audit Metadata