design-spec-extraction

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted visual inputs (screenshots) which can contain embedded instructions aimed at the analyzing agent.
  • Ingestion points: Visual inputs are ingested in Pass 1 through Pass 6 as defined in the subtask agent prompts within SKILL.md.
  • Boundary markers: The skill lacks explicit boundary markers or instructions for subtask agents to ignore or sanitize embedded visual text during the analysis passes.
  • Capability inventory: The skill utilizes shell commands (mkdir), a Write tool for saving JSON files to the local file system, a Read tool for loading intermediate data, and a delegate action for task orchestration across multiple sub-agents.
  • Sanitization: There is no evidence of sanitization or validation of the content extracted from visual sources before it is persisted to disk or passed to downstream agents for consolidation.
  • [COMMAND_EXECUTION]: The skill instructions involve the execution of shell commands to manage the extraction environment.
  • Evidence: The execution instructions in SKILL.md specify using mkdir -p .tmp-design-specs/{project-name} to create directory structures for storing intermediate extraction artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — design-spec-extraction