design-spec-extraction
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted visual inputs (screenshots) which can contain embedded instructions aimed at the analyzing agent.
- Ingestion points: Visual inputs are ingested in Pass 1 through Pass 6 as defined in the subtask agent prompts within
SKILL.md. - Boundary markers: The skill lacks explicit boundary markers or instructions for subtask agents to ignore or sanitize embedded visual text during the analysis passes.
- Capability inventory: The skill utilizes shell commands (
mkdir), aWritetool for saving JSON files to the local file system, aReadtool for loading intermediate data, and adelegateaction for task orchestration across multiple sub-agents. - Sanitization: There is no evidence of sanitization or validation of the content extracted from visual sources before it is persisted to disk or passed to downstream agents for consolidation.
- [COMMAND_EXECUTION]: The skill instructions involve the execution of shell commands to manage the extraction environment.
- Evidence: The execution instructions in
SKILL.mdspecify usingmkdir -p .tmp-design-specs/{project-name}to create directory structures for storing intermediate extraction artifacts.
Audit Metadata