design-system-creator

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill utilizes the mcp__firecrawl__firecrawl_search tool to fetch design information from the web, which creates a vulnerability to instructions hidden in external content. * Ingestion points: External data enters the agent context through the firecrawl_search tool referenced in SKILL.md. * Boundary markers: The instructions lack delimiters or specific directives to ignore instructions found within retrieved web data. * Capability inventory: The skill possesses filesystem Write and Edit permissions and utilizes component building tools. * Sanitization: No sanitization, validation, or filtering of the ingested external content is specified before the data influences the agent's output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — design-system-creator