aesthetic

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow to capture and analyze screenshots from external design inspiration websites (e.g., Dribbble, Mobbin, Behance). This introduces an indirect prompt injection surface where malicious text or instructions placed on those websites could be ingested and acted upon by the agent during the analysis phase.
  • Ingestion points: External websites visited via chrome-devtools and analyzed via ai-multimodal as described in SKILL.md.
  • Boundary markers: Absent. The instructions do not define delimiters or provide warnings for the agent to disregard instructions found within the processed screenshots.
  • Capability inventory: The skill integrates with ui-styling and web-frameworks for file generation, and media-processing for command-line image/video manipulation.
  • Sanitization: Absent. There is no verification or sanitization process for the design guidelines extracted from external sources.
  • [COMMAND_EXECUTION]: The references/design-resources.md file suggests using gallery-dl via the bash tool to download reference images. Encouraging the use of shell commands to process content from arbitrary external URLs increases the risk of command injection or malicious payload execution if the tool is used on untrusted inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:41 AM
Security Audit — agent-trust-hub — aesthetic