web-design-expert
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a custom Node.js auditing script (
scripts/design_audit.mjs) used to validate design plans against defined quality gates at runtime. - [COMMAND_EXECUTION]: The skill instructs the agent to execute a Python script located at an external path (
~/.claude/skills/layout-overflow-guard/scripts/check_layout.py) to perform layout validation and collision checking. This creates a dependency on an external skill's binary/script. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, potentially untrusted brand briefs and design plans which could contain malicious instructions.
- Ingestion points: The skill processes
brand-audience-brief(Markdown) anddesign-plan(JSON) as specified in its I/O contract. - Boundary markers: The instructions do not define clear delimiters or warnings to ignore embedded instructions within these ingested files.
- Capability inventory: The skill possesses powerful capabilities, including file system access (
Read,Write,Edit), network fetching (WebFetch), specialized UI generation tools (mcp__magic__*), and shell command execution (node,python3). - Sanitization: The accompanying
design_audit.mjsscript performs basic type validation (boolean, number, object) on the JSON input before using the data in its audit logic.
Audit Metadata