design-critic

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from both local project files and external web pages to perform its critique, creating a vulnerability surface where malicious instructions embedded in a design could influence the agent's behavior.
  • Ingestion points: The skill uses the WebFetch tool to retrieve content from external URLs and the Read, Glob, and Grep tools to access local source code and design component files.
  • Boundary markers: The instructions do not define clear delimiters or provide "ignore embedded instructions" warnings to help the agent distinguish between data to be critiqued and potential malicious prompts within that data.
  • Capability inventory: The skill possesses significant capabilities, including reading local files and performing network requests to arbitrary domains.
  • Sanitization: No content validation, escaping, or sanitization routines are implemented for the external or local data processed by the skill.
  • [DATA_EXFILTRATION]: The skill is configured to use network-enabled tools such as WebFetch and WebSearch to interact with domains outside of the standard whitelist. While this is necessary for its stated purpose of auditing live websites, it establishes a communication channel to non-whitelisted external servers that could be misused.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:31 AM
Security Audit — agent-trust-hub — design-critic