interaction-designer

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md file uses dynamic context injection (!command) to execute cat commands on local protocol and configuration files. This hydration process allows the agent to load project-specific design rules from ux-protocol.md, design-mindset-and-rules.md, and .production-grade.yaml.
  • [COMMAND_EXECUTION]: The LITE.md file instructs the agent to execute diagnostic shell commands (find, cat, jq, ls) to discover project dependencies and documentation structures within the local filesystem.
  • [PROMPT_INJECTION]: The skill contains a potential surface for indirect prompt injection as it processes project-level files to generate UI components and specifications. Evidence Chain: Ingestion points include .production-grade.yaml, package.json, and the docs/ directory; no boundary markers or sanitization are specified; the agent has the capability to write React components to src/components/.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — interaction-designer