canvas-design-decomposition

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing external, untrusted content which could contain adversarial instructions aimed at influencing the resulting component architecture or downstream implementation tasks.
  • Ingestion points: Ingests data from Figma frames, external websites via scraping tools, screenshots, and text-based briefs provided in user messages (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external content as data only and ignore embedded directives.
  • Capability inventory: The output of this skill directly influences subsequent high-capability tasks including folder creation, metadata authoring, and visual implementation in linked skills.
  • Sanitization: The workflow lacks a validation or sanitization step to check for malicious content within design metadata or scraped HTML before the decomposition analysis begins.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:11 PM
Security Audit — agent-trust-hub — canvas-design-decomposition