aesthetic
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a workflow to capture and analyze screenshots from external design inspiration websites (e.g., Dribbble, Mobbin, Behance). This introduces an indirect prompt injection surface where malicious text or instructions placed on those websites could be ingested and acted upon by the agent during the analysis phase.
- Ingestion points: External websites visited via
chrome-devtoolsand analyzed viaai-multimodalas described inSKILL.md. - Boundary markers: Absent. The instructions do not define delimiters or provide warnings for the agent to disregard instructions found within the processed screenshots.
- Capability inventory: The skill integrates with
ui-stylingandweb-frameworksfor file generation, andmedia-processingfor command-line image/video manipulation. - Sanitization: Absent. There is no verification or sanitization process for the design guidelines extracted from external sources.
- [COMMAND_EXECUTION]: The
references/design-resources.mdfile suggests usinggallery-dlvia thebashtool to download reference images. Encouraging the use of shell commands to process content from arbitrary external URLs increases the risk of command injection or malicious payload execution if the tool is used on untrusted inputs.
Audit Metadata