top-design
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to evaluate and refactor web designs which involves ingesting user-provided landing pages and design descriptions. This creates an attack surface where malicious instructions could be embedded in the content being analyzed.
- Ingestion points: User-provided landing pages and design descriptions processed via the 'Top-Design' scoring and refactoring prompts in SKILL.md.
- Boundary markers: No specific delimiters or 'ignore instructions' directives are provided to isolate user content.
- Capability inventory: The skill provides design patterns and reference code (CSS/JS); it does not invoke privileged system tools, executables, or network operations.
- Sanitization: The instructions do not define filtering or sanitization for embedded prompt injections in external content.
- [METADATA_POISONING]: There is an inconsistency in the author attribution between the skill context and the metadata.
- Evidence: The SKILL.md YAML frontmatter and affiliate tags in the 'Further Reading' section reference 'wondelai', while the external distribution context identifies 'emmraan' as the author.
Audit Metadata