web-design-expert
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which represents a vulnerability surface for indirect prompt injection attacks.
- Ingestion points: The skill retrieves data from external sources via
WebFetch,mcp__magic__21st_magic_component_inspiration,mcp__magic__logo_search, and various Figma MCPs as documented inreferences/tooling-integration.md. - Boundary markers: There are no explicit instructions or delimiters defined within the skill to isolate external content or warn the agent against executing embedded instructions found in these sources.
- Capability inventory: The skill is granted
WriteandEditpermissions and utilizes themcp__magic__21st_magic_component_buildertool to generate and output production-ready React and Tailwind code (noted inSKILL.mdandreferences/tooling-integration.md). - Sanitization: The skill lacks defined sanitization, validation, or filtering mechanisms for the data ingested from external APIs or design files.
Audit Metadata