design-archivist

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to perform systematic crawls of 500-1000 external website examples, which exposes the agent to untrusted data that could contain malicious instructions.
  • Ingestion points: External data is ingested from untrusted third-party websites using WebFetch and WebSearch as described in the Core Process section of SKILL.md.
  • Boundary markers: The skill lacks explicit instructions for using delimiters or boundary markers to isolate external content, increasing the risk that the agent may follow instructions embedded within the scraped design examples.
  • Capability inventory: The skill possesses file write capabilities (Write tool for checkpoints) and network access (WebFetch/WebSearch), which could be misused if the agent is influenced by injected content.
  • Sanitization: There are no defined procedures for sanitizing or filtering instructions from the HTML and visual data extracted during the crawl.
  • [COMMAND_EXECUTION]: The skill package includes a shell script (scripts/validate_archive.sh) intended for local execution to verify output integrity.
  • Evidence: The script uses the jq utility to perform structural and logic checks on the generated design database. It does not perform network operations or require elevated privileges, serving as a static validation utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:02 PM
Security Audit — agent-trust-hub — design-archivist