skills/delorenj/skills/taste-design/Gen Agent Trust Hub

taste-design

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data in the form of project intent and 'vibe descriptions' to generate a DESIGN.md file. This file is written to the filesystem using the Write tool. There are no explicit instructions to sanitize this input or use boundary markers to prevent user-supplied instructions from influencing the generated output in a malicious way.
  • Ingestion points: Project intent and 'vibe description' evaluated in SKILL.md.
  • Boundary markers: None identified in the output generation instructions.
  • Capability inventory: Uses the Write tool to persist generated content and StitchMCP for integration.
  • Sanitization: No validation or sanitization logic is specified for the user's input.
  • [SAFE]: The skill references picsum.photos as a recommended source for placeholder images in design documents, which is a well-known and standard service for this purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — taste-design