skills/catcatcatstudio/cat-skills/eye/Gen Agent Trust Hub

eye

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues or malicious patterns were detected in this skill.
  • [DATA_EXFILTRATION]: The skill involves navigating to URLs or localhost to perform design analysis. This is a core functionality initiated by explicit user commands (e.g., /eye [URL]) and does not demonstrate any unauthorized data movement.
  • [PROMPT_INJECTION]: The instructions establish a professional 'design director' persona. There are no attempts to bypass safety filters, extract system prompts, or override agent behavior beyond the intended role-play for design critique.
  • [COMMAND_EXECUTION]: No dangerous shell commands or unauthorized subprocess executions were identified. Tool usage is limited to standard browser interaction for analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content (websites and local code) as part of its primary design review function. While this creates a surface for indirect prompt injection, it is necessary for the skill's purpose and the risk is mitigated by the agent's focus on visual and structural analysis.
  • Ingestion points: Browser navigation to user-provided URLs or localhost, and reading project source code (SKILL.md).
  • Boundary markers: None explicitly defined for untrusted content.
  • Capability inventory: Screenshotting, browsing, and interaction (hover, click) via browser tools.
  • Sanitization: No specific sanitization of external HTML/CSS content is mentioned before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:50 AM
Security Audit — agent-trust-hub — eye