design-extractor
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to crawl and process data from external websites, which is an untrusted source. Maliciously crafted content on these sites could attempt to influence the agent's behavior.
- Ingestion points:
SKILL.md(Step 3) instructions the agent to crawl various subpages of a website (/login,/pricing,/blog, etc.) and ingest their content. - Boundary markers: The instructions lack clear delimiters or warnings to ignore instructions that might be hidden within the fetched HTML or CSS.
- Capability inventory: The agent has the ability to execute shell commands (
curl), run Python scripts, and write files to the local directory. - Sanitization: There is no mention of sanitizing or filtering the content retrieved from the web before it is analyzed or written to the output file.
- [COMMAND_EXECUTION]: The "Completo" mode described in
SKILL.md(Step 2) involves using shell commands such ascurlor Python scripts to download and parse site assets (HTML/CSS). - [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch data from external URLs provided by the user and related subpages discovered during the crawling process.
Audit Metadata