web-design-expert

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface within its automated design-to-code integration workflow.
  • Ingestion points: The skill ingests external untrusted data when retrieving UI patterns via 21st_magic_component_inspiration or extracting structural text, typography specs, and names from user-provided Figma URLs as specified in references/tooling-integration.md.
  • Boundary markers: There are no system-level delimiters or guardrails instructing the agent to ignore prompt injections or malicious commands hidden within design layer names, component names, or description parameters.
  • Capability inventory: The skill maintains high-privilege capabilities including the ability to write and edit files locally (Write, Edit) and invoke specialized AI component generation tools (mcp__magic__21st_magic_component_builder).
  • Sanitization: No sanitization or verification protocols are defined to validate data fetched via MCP servers from external source files before passing it directly into the code generation pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:27 AM
Security Audit — agent-trust-hub — web-design-expert