design-archivist
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to perform systematic crawls of 500-1000 external website examples, which exposes the agent to untrusted data that could contain malicious instructions.
- Ingestion points: External data is ingested from untrusted third-party websites using WebFetch and WebSearch as described in the Core Process section of SKILL.md.
- Boundary markers: The skill lacks explicit instructions for using delimiters or boundary markers to isolate external content, increasing the risk that the agent may follow instructions embedded within the scraped design examples.
- Capability inventory: The skill possesses file write capabilities (Write tool for checkpoints) and network access (WebFetch/WebSearch), which could be misused if the agent is influenced by injected content.
- Sanitization: There are no defined procedures for sanitizing or filtering instructions from the HTML and visual data extracted during the crawl.
- [COMMAND_EXECUTION]: The skill package includes a shell script (scripts/validate_archive.sh) intended for local execution to verify output integrity.
- Evidence: The script uses the jq utility to perform structural and logic checks on the generated design database. It does not perform network operations or require elevated privileges, serving as a static validation utility.
Audit Metadata