design-language
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze potentially untrusted data from external sources, including website URLs, frontend source code, and CSS files, which can contain hidden instructions targeting the LLM.
- Ingestion points: Website URLs, frontend source code, design files, and CSS (referenced in SKILL.md under "Supported Inputs").
- Boundary markers: The skill lacks instructions for using delimiters or explicit "ignore" warnings when processing these external data sources.
- Capability inventory: The skill leverages the agent's ability to read external content and generate structured specifications, creating a path for embedded instructions in the analyzed data to influence the output.
- Sanitization: There are no provided instructions for sanitizing or validating the integrity of the external content before analysis.
Audit Metadata