design-extractor

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to crawl and process data from external websites, which is an untrusted source. Maliciously crafted content on these sites could attempt to influence the agent's behavior.
  • Ingestion points: SKILL.md (Step 3) instructions the agent to crawl various subpages of a website (/login, /pricing, /blog, etc.) and ingest their content.
  • Boundary markers: The instructions lack clear delimiters or warnings to ignore instructions that might be hidden within the fetched HTML or CSS.
  • Capability inventory: The agent has the ability to execute shell commands (curl), run Python scripts, and write files to the local directory.
  • Sanitization: There is no mention of sanitizing or filtering the content retrieved from the web before it is analyzed or written to the output file.
  • [COMMAND_EXECUTION]: The "Completo" mode described in SKILL.md (Step 2) involves using shell commands such as curl or Python scripts to download and parse site assets (HTML/CSS).
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch data from external URLs provided by the user and related subpages discovered during the crawling process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 12:04 AM
Security Audit — agent-trust-hub — design-extractor