native-app-designer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill integrates external, untrusted data from web searches into the agent's execution context, creating a surface for indirect prompt injection. (1) Ingestion points: External web content retrieved via the mcp__firecrawl__firecrawl_search tool and component inspiration from 21st.dev via the mcp__magic__21st_magic_component_builder tool. (2) Boundary markers: Absent. The skill provides no instructions to wrap external content in delimiters or to disregard embedded instructions within fetched data. (3) Capability inventory: The agent is granted powerful capabilities including Bash, Write, and Edit as listed in allowed-tools, which could be abused if the agent obeys malicious instructions embedded in search results. (4) Sanitization: Absent. There are no guidelines for the agent to sanitize, escape, or validate the integrity of data returned by external tools before acting upon it.
Audit Metadata