design-critic
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from both local project files and external web pages to perform its critique, creating a vulnerability surface where malicious instructions embedded in a design could influence the agent's behavior.
- Ingestion points: The skill uses the
WebFetchtool to retrieve content from external URLs and theRead,Glob, andGreptools to access local source code and design component files. - Boundary markers: The instructions do not define clear delimiters or provide "ignore embedded instructions" warnings to help the agent distinguish between data to be critiqued and potential malicious prompts within that data.
- Capability inventory: The skill possesses significant capabilities, including reading local files and performing network requests to arbitrary domains.
- Sanitization: No content validation, escaping, or sanitization routines are implemented for the external or local data processed by the skill.
- [DATA_EXFILTRATION]: The skill is configured to use network-enabled tools such as
WebFetchandWebSearchto interact with domains outside of the standard whitelist. While this is necessary for its stated purpose of auditing live websites, it establishes a communication channel to non-whitelisted external servers that could be misused.
Audit Metadata