skills/duc01226/easyplatform/design/Gen Agent Trust Hub

design

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill architecture is well-structured and follows expected patterns for high-quality AI agent task management. No malicious obfuscation, hidden URLs, or credential exfiltration attempts were detected.
  • [COMMAND_EXECUTION]: The skill invokes local utility scripts to facilitate design research and media processing. These operations are aligned with the skill's primary function and target local paths (e.g., python $HOME/.claude/skills/ui-ux-pro-max/scripts/search.py, python scripts/gemini_batch_process.py, python scripts/media_optimizer.py).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied briefs, images, and videos. It manages the attack surface by using structured task tracking and subagent orchestration, providing boundaries for input processing. The following evidence chain was evaluated:
  • Ingestion points: The skill accepts text design briefs, screenshots, and videos via $ARGUMENTS in SKILL.md.
  • Boundary markers: Work is divided into discrete tasks using <tasks> tags for the agent.
  • Capability inventory: The agent has access to shell execution (Python scripts), subagent spawning (spawn_agent), and file system writes (updating design documentation).
  • Sanitization: No explicit sanitization of input arguments is described, though the multi-stage spine (Research, Ingest, Design, Implement, Document) naturally limits direct data flow to sensitive operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:22 PM
Security Audit — agent-trust-hub — design