web-visual-direction

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is focused on design methodology and contains no malicious code, unauthorized system commands, or exfiltration logic. The instructions and references are descriptive and task-oriented.
  • [NO_CODE]: The skill consists entirely of markdown documentation and YAML configuration files, with no executable scripts, binaries, or automated shell commands.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from product briefs and existing code to inform its visual direction and implementation, creating a standard indirect prompt injection surface.
  • Ingestion points: The agent is instructed to inspect product briefs, existing code, and brand assets in SKILL.md.
  • Boundary markers: Absent; the instructions do not specify delimiters for external content or warnings to ignore embedded instructions.
  • Capability inventory: The skill has the capability to implement UI components and viewports based on the analyzed design direction.
  • Sanitization: No input validation or sanitization of the external project data is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 03:29 PM
Security Audit — agent-trust-hub — web-visual-direction