web-design-expert
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface within its automated design-to-code integration workflow.
- Ingestion points: The skill ingests external untrusted data when retrieving UI patterns via
21st_magic_component_inspirationor extracting structural text, typography specs, and names from user-provided Figma URLs as specified inreferences/tooling-integration.md. - Boundary markers: There are no system-level delimiters or guardrails instructing the agent to ignore prompt injections or malicious commands hidden within design layer names, component names, or description parameters.
- Capability inventory: The skill maintains high-privilege capabilities including the ability to write and edit files locally (
Write,Edit) and invoke specialized AI component generation tools (mcp__magic__21st_magic_component_builder). - Sanitization: No sanitization or verification protocols are defined to validate data fetched via MCP servers from external source files before passing it directly into the code generation pipeline.
Audit Metadata